NULL pointer dereference in ImageMagick - CVE-2016-5690
Published: December 13, 2016 / Updated: July 28, 2020
Vulnerability identifier: #VU32208
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5690
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
The ReadDCMImage function in DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact via vectors involving the for statement in computing the pixel scaling table.
Affected software
ImageMagick
imagemagick (Alpine package)
imagemagick (Alpine package)
How to mitigate CVE-2016-5690
Install update from vendor's website.
ImageMagick - update to 7.0.1-7
imagemagick (Alpine package) - update to 6.9.6.8-r0
imagemagick (Alpine package) - update to 6.9.6.8-r0
External References
- http://www.openwall.com/lists/oss-security/2016/06/14/5
- http://www.openwall.com/lists/oss-security/2016/06/17/3
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
- http://www.securityfocus.com/bid/91283
- https://blog.fuzzing-project.org/46-Various-invalid-memory-reads-in-ImageMagick-WPG,-DDS,-DCM.html
- https://github.com/ImageMagick/ImageMagick/blob/6.9.4-5/ChangeLog
- https://github.com/ImageMagick/ImageMagick/blob/7.0.1-7/ChangeLog
- https://github.com/ImageMagick/ImageMagick/commit/5511ef530576ed18fd636baa3bb4eda3d667665d