CVE-2016-6520Out-of-bounds Read in Imagemagick

CWE-125Out-of-bounds Read6 documents5 sources
Severity
9.1CRITICALNVD
EPSS
3.4%
top 12.54%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 13
Latest updateMay 13

Description

Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows remote attackers to have unspecified impact via vectors related to pixel cache morphology.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:HExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

NVDimagemagick/imagemagick7.0.0-07.0.2-7

Patches

🔴Vulnerability Details

1
GHSA
GHSA-mg49-wc47-228m: Buffer overflow in MagickCore/enhance2022-05-13

📋Vendor Advisories

2
Red Hat
ImageMagick: out-of-bounds read in enhance.c2016-08-01
Debian
CVE-2016-6520: imagemagick - Buffer overflow in MagickCore/enhance.c in ImageMagick before 7.0.2-7 allows rem...2016

💬Community

2
Bugzilla
CVE-2016-6520 ImageMagick: out-of-bounds read in enhance.c2016-08-05
Bugzilla
CVE-2016-6520 ImageMagick: Buffer overflow in enhance.c [fedora-all]2016-08-05