Heap-based buffer overflow in ImageMagick - CVE-2016-9773
Published: February 17, 2017 / Updated: August 10, 2020
ImageMagick
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error in Heap-based buffer overflow in the IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.8. A remote attacker can use a crafted image file. NOTE to trigger heap-based buffer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
How to mitigate CVE-2016-9773
Sources
- http://www.openwall.com/lists/oss-security/2016/12/01/4
- http://www.openwall.com/lists/oss-security/2016/12/02/11
- http://www.openwall.com/lists/oss-security/2016/12/02/12
- https://blogs.gentoo.org/ago/2016/12/01/imagemagick-heap-based-buffer-overflow-in-ispixelgray-pixel-accessor-h-incomplete-fix-for-cve-2016-9556/