4.3
CVSSv2

CVE-2016-9556

Published: 23/03/2017 Updated: 24/03/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The IsPixelGray function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3-8 allows remote malicious users to cause a denial of service (out-of-bounds heap read) via a crafted image file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick 7.0.3-8

opensuse project leap 42.1

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #845242 imagemagick: CVE-2016-9556: Heap buffer overflow in heap-buffer-overflow in IsPixelGray Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Dat ...
Several security issues were fixed in ImageMagick ...
Several issues have been discovered in ImageMagick, a popular set of programs and libraries for image manipulation These issues include several problems in memory handling that can result in a denial of service attack or in execution of arbitrary code by an attacker with control on the image input For the stable distribution (jessie), these probl ...
The IsPixelGray function in MagickCore/pixel-accessorh in ImageMagick 703-8 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted image file ...