Denial of service - CVE-2016-7799

 

Denial of service - CVE-2016-7799

Published: October 8, 2016 / Updated: October 11, 2016


Vulnerability identifier: #VU834
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-7799
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote unauthenticated user to cause DoS conditions on the vulnerable system.
The weakness exists due to buffer over read caused by malicious file and allowing attackers to cause the affected application to crash.
Successful exploitation of the vulnerability results in denial of service on the vulnerable system.

Affected software

Arch Linux
Gentoo Linux
imagemagick (Alpine package)

How to mitigate CVE-2016-7799

Update to version 6.9.6.0-1.

imagemagick (Alpine package) - update to 6.9.6.8-r0

External References

Related Security Bulletins