CVE-2016-2317
Severity
5.5MEDIUM
EPSS
0.2%
top 51.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 3
Latest updateMay 14
Description
Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in magick/utility.c, and (3) GetTransformTokens function in coders/svg.c.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages7 packages
Also affects: Debian Linux 8.0
🔴Vulnerability Details
3📋Vendor Advisories
1Debian▶
CVE-2016-2317: graphicsmagick - Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cau...↗2016
💬Community
4Bugzilla▶
CVE-2016-7446 CVE-2016-7447 CVE-2016-7448 CVE-2016-7449 GraphicsMagick: various issues fixed in 1.3.25↗2016-09-08