CVE-2016-10069Improper Input Validation in Imagemagick

Severity
5.5MEDIUMNVD
EPSS
0.6%
top 31.34%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 2
Latest updateMay 17

Description

coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a mat file with an invalid number of frames.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

Debianimagemagick/imagemagick< 8:6.9.6.2+dfsg-2+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-q748-7h9v-72m4: coders/mat2022-05-17
OSV
CVE-2016-10069: coders/mat2017-03-02
CVEList
CVE-2016-10069: coders/mat2017-03-02

📋Vendor Advisories

2
Red Hat
ImageMagick: Invalid number of frames not checked in mat files2016-05-29
Debian
CVE-2016-10069: imagemagick - coders/mat.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a de...2016

💬Community

1
Bugzilla
CVE-2016-10069 ImageMagick: Invalid number of frames not checked in mat files2017-01-05
CVE-2016-10069 — Improper Input Validation | cvebase