CVE-2016-5688
published 2016-12-13CVE-2016-5688: The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors…
PriorityP348high8.1CVSS 3.0
AVNACHPRNUINSUCHIHAH
EPSS
4.82%
91.0th percentile
The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.9.6.2+dfsg-2 (bookworm) | imagemagick 8:6.9.6.2+dfsg-2 (bookworm) |
| imagemagick | imagemagick | <= 6.9.4-3 | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| oracle | solaris | — | — |
CVSS provenance
nvdv3.08.1HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.1HIGH
vendor_debian8.1HIGH
vendor_redhat8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2hhc-539m-8qw5: The WPG parser in ImageMagick before 6
ghsa_unreviewed·2022-05-17
CVE-2016-5688 [HIGH] CWE-119 GHSA-2hhc-539m-8qw5: The WPG parser in ImageMagick before 6
The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.
OSV
CVE-2016-5688: The WPG parser in ImageMagick before 6
osv·2016-12-13·CVSS 8.1
CVE-2016-5688 [HIGH] CVE-2016-5688: The WPG parser in ImageMagick before 6
The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2016-11-21
CVE-2014-8354 ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled certain malformed
image files. If a user or automated system using ImageMagick were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service or possibly execute code with the privileges of
the user invoking the program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ImageMagick: Heap overflow and random invalid memory writes in WPg parser
vendor_redhat·2016-06-14·CVSS 8.1
CVE-2016-5688 [HIGH] CWE-122 ImageMagick: Heap overflow and random invalid memory writes in WPg parser
ImageMagick: Heap overflow and random invalid memory writes in WPg parser
The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Under investigation
Package: ImageMagick (Red Hat Enterprise Linux 6) - Affected
Package: ImageMagick (Red Hat Enterprise Linux 7) - Affected
Package: ImageMagick (Red Hat OpenShift Enterprise 2) - Affected
Debian
CVE-2016-5688: imagemagick - The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memo...
vendor_debian·2016·CVSS 8.1
CVE-2016-5688 [HIGH] CVE-2016-5688: imagemagick - The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memo...
The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6.2+dfsg-2)
sid: resolved (fixed in 8:6.9.6.2+dfsg-2)
trixie: resolved (fixed in 8:6.9.6.2+dfsg-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5687 CVE-2016-5688 CVE-2016-5689 CVE-2016-5690 CVE-2016-5691 imagemagick: various flaws [fedora-all]
bugzilla·2016-06-20·CVSS 9.8
CVE-2016-5687 [CRITICAL] CVE-2016-5687 CVE-2016-5688 CVE-2016-5689 CVE-2016-5690 CVE-2016-5691 imagemagick: various flaws [fedora-all]
CVE-2016-5687 CVE-2016-5688 CVE-2016-5689 CVE-2016-5690 CVE-2016-5691 imagemagick: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects
Bugzilla
CVE-2016-5688 ImageMagick: Heap overflow and random invalid memory writes in WPg parser
bugzilla·2016-06-20·CVSS 8.1
CVE-2016-5688 [HIGH] CVE-2016-5688 ImageMagick: Heap overflow and random invalid memory writes in WPg parser
CVE-2016-5688 ImageMagick: Heap overflow and random invalid memory writes in WPg parser
Several bugs in the WPG parser were found that could lead to a heap overflow and random invalid memory writes. These bugs only seem to appear when a memory limit is set.
Upstream patches:
https://github.com/ImageMagick/ImageMagick/commit/fc43974d34318c834fbf78570ca1a3764ed8c7d7
https://github.com/ImageMagick/ImageMagick/commit/aecd0ada163a4d6c769cec178955d5f3e9316f2f
External References:
https://blog.fuzzing-project.org/46-Various-invalid-memory-reads-in-ImageMagick-WPG,-DDS,-DCM.html
CVE assignment:
http://seclists.org/oss-sec/2016/q2/564
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1348173]
http://www.openwall.com/lists/oss-security/2016/06/14/5http://www.openwall.com/lists/oss-security/2016/06/17/3http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/91283https://blog.fuzzing-project.org/46-Various-invalid-memory-reads-in-ImageMagick-WPG%2C-DDS%2C-DCM.htmlhttps://github.com/ImageMagick/ImageMagick/commit/aecd0ada163a4d6c769cec178955d5f3e9316f2fhttps://github.com/ImageMagick/ImageMagick/commit/fc43974d34318c834fbf78570ca1a3764ed8c7d7https://github.com/ImageMagick/ImageMagick/commits/6.9.4-4https://github.com/ImageMagick/ImageMagick/commits/7.0.1-5http://www.openwall.com/lists/oss-security/2016/06/14/5http://www.openwall.com/lists/oss-security/2016/06/17/3http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlhttp://www.securityfocus.com/bid/91283https://blog.fuzzing-project.org/46-Various-invalid-memory-reads-in-ImageMagick-WPG%2C-DDS%2C-DCM.htmlhttps://github.com/ImageMagick/ImageMagick/commit/aecd0ada163a4d6c769cec178955d5f3e9316f2fhttps://github.com/ImageMagick/ImageMagick/commit/fc43974d34318c834fbf78570ca1a3764ed8c7d7https://github.com/ImageMagick/ImageMagick/commits/6.9.4-4https://github.com/ImageMagick/ImageMagick/commits/7.0.1-5
2016-12-13
Published