Buffer overflow in the Get8BIMProperty function in MagickCore/property.c in ImageMagick before 6.9.5-4 and 7.x before 7.0.2-6 allows remote attackers to cause a denial of service (out-of-bounds read, memory leak, and crash) via a crafted image.
The product reads data past the end, or before the beginning, of the intended buffer.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Imagemagick | Imagemagick | * | 6.9.5-3 (including) |
Imagemagick | Imagemagick | 7.0.1-0 (including) | 7.0.1-0 (including) |
Imagemagick | Imagemagick | 7.0.1-1 (including) | 7.0.1-1 (including) |
Imagemagick | Imagemagick | 7.0.1-2 (including) | 7.0.1-2 (including) |
Imagemagick | Imagemagick | 7.0.1-3 (including) | 7.0.1-3 (including) |
Imagemagick | Imagemagick | 7.0.1-4 (including) | 7.0.1-4 (including) |
Imagemagick | Imagemagick | 7.0.1-5 (including) | 7.0.1-5 (including) |
Imagemagick | Imagemagick | 7.0.1-6 (including) | 7.0.1-6 (including) |
Imagemagick | Imagemagick | 7.0.1-7 (including) | 7.0.1-7 (including) |
Imagemagick | Imagemagick | 7.0.1-8 (including) | 7.0.1-8 (including) |
Imagemagick | Imagemagick | 7.0.1-9 (including) | 7.0.1-9 (including) |
Imagemagick | Imagemagick | 7.0.1-10 (including) | 7.0.1-10 (including) |
Imagemagick | Imagemagick | 7.0.2-0 (including) | 7.0.2-0 (including) |
Imagemagick | Imagemagick | 7.0.2-1 (including) | 7.0.2-1 (including) |
Imagemagick | Imagemagick | 7.0.2-2 (including) | 7.0.2-2 (including) |
Imagemagick | Imagemagick | 7.0.2-3 (including) | 7.0.2-3 (including) |
Imagemagick | Imagemagick | 7.0.2-4 (including) | 7.0.2-4 (including) |
Imagemagick | Imagemagick | 7.0.2-5 (including) | 7.0.2-5 (including) |
Imagemagick | Ubuntu | devel | * |
Imagemagick | Ubuntu | precise | * |
Imagemagick | Ubuntu | trusty | * |
Imagemagick | Ubuntu | upstream | * |
Imagemagick | Ubuntu | wily | * |
Imagemagick | Ubuntu | xenial | * |
Imagemagick | Ubuntu | yakkety | * |