7.5
CVSSv3

CVE-2016-6823

Published: 18/01/2017 Updated: 28/04/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

Integer overflow in the BMP coder in ImageMagick prior to 7.0.2-10 allows remote malicious users to cause a denial of service (crash) via crafted height and width values, which triggers an out-of-bounds write.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick

Vendor Advisories

Debian Bug report logs - #834504 imagemagick: CVE-2016-6823: Buffer overflow in bmp file reader Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Tue, 16 Aug 2016 12:03 ...
Several security issues were fixed in ImageMagick ...
This updates fixes many vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service or the execution of arbitrary code if malformed TIFF, WPG, RLE, RAW, PSD, Sun, PICT, VIFF, HDR, Meta, Quantum, PDB, DDS, DCM, EXIF, RGF or BMP files are processed For the stabl ...
Integer overflow in the BMP coder in ImageMagick before 702-10 allows remote attackers to cause a denial of service (crash) via crafted height and width values, which triggers an out-of-bounds write ...