CVE-2016-7513
published 2017-04-20CVE-2016-7513: Off-by-one error in magick/cache.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors.
PriorityP425medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.49%
82.8th percentile
Off-by-one error in magick/cache.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.9.6.2+dfsg-2 (bookworm) | imagemagick 8:6.9.6.2+dfsg-2 (bookworm) |
| imagemagick | imagemagick | < 6.9.4-0 | 6.9.4-0 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6fpf-rm62-frrc: Off-by-one error in magick/cache
ghsa_unreviewed·2022-05-17
CVE-2016-7513 [MEDIUM] GHSA-6fpf-rm62-frrc: Off-by-one error in magick/cache
Off-by-one error in magick/cache.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors.
OSV
CVE-2016-7513: Off-by-one error in magick/cache
osv·2017-04-20·CVSS 6.5
CVE-2016-7513 [MEDIUM] CVE-2016-7513: Off-by-one error in magick/cache
Off-by-one error in magick/cache.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2016-11-21
CVE-2014-8354 ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled certain malformed
image files. If a user or automated system using ImageMagick were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service or possibly execute code with the privileges of
the user invoking the program.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2016-7513: imagemagick - Off-by-one error in magick/cache.c in ImageMagick allows remote attackers to cau...
vendor_debian·2016·CVSS 6.5
CVE-2016-7513 [MEDIUM] CVE-2016-7513: imagemagick - Off-by-one error in magick/cache.c in ImageMagick allows remote attackers to cau...
Off-by-one error in magick/cache.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6.2+dfsg-2)
sid: resolved (fixed in 8:6.9.6.2+dfsg-2)
trixie: resolved (fixed in 8:6.9.6.2+dfsg-2)
Red Hat
ImageMagick: Off-by-one error in cache.c
vendor_redhat·2014-12-16·CVSS 6.5
CVE-2016-7513 [MEDIUM] CWE-193 ImageMagick: Off-by-one error in cache.c
ImageMagick: Off-by-one error in cache.c
Off-by-one error in magick/cache.c in ImageMagick allows remote attackers to cause a denial of service (segmentation fault) via unspecified vectors.
Statement: This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 6) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 7) - Not affected
Package: ImageMagick (Red Hat OpenShift Enterprise 2) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9907 CVE-2015-8957 CVE-2015-8958 CVE-2015-8959 CVE-2016-6823 CVE-2016-7101 CVE-2016-7513 CVE-2016-7514 CVE-2016-7515 CVE-2016-7516 CVE-2016-7517 CVE-2016-7518 CVE-2016-7519 CVE-2016-7520 CVE-
bugzilla·2016-09-23·CVSS 6.5
CVE-2014-9907 [MEDIUM] CVE-2014-9907 CVE-2015-8957 CVE-2015-8958 CVE-2015-8959 CVE-2016-6823 CVE-2016-7101 CVE-2016-7513 CVE-2016-7514 CVE-2016-7515 CVE-2016-7516 CVE-2016-7517 CVE-2016-7518 CVE-2016-7519 CVE-2016-7520 CVE-
CVE-2014-9907 CVE-2015-8957 CVE-2015-8958 CVE-2015-8959 CVE-2016-6823 CVE-2016-7101 CVE-2016-7513 CVE-2016-7514 CVE-2016-7515 CVE-2016-7516 CVE-2016-7517 CVE-2016-7518 CVE-2016-7519 CVE-2016-7520 CVE-2016-7521 ... ImageMagick: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevan
Bugzilla
CVE-2016-7513 ImageMagick: Off-by-one error in cache.c
bugzilla·2016-09-23·CVSS 6.5
CVE-2016-7513 [MEDIUM] CVE-2016-7513 ImageMagick: Off-by-one error in cache.c
CVE-2016-7513 ImageMagick: Off-by-one error in cache.c
An off-by-one error leading to a segmentation fault was found in ImageMagick.
Debian bug:
https://bugs.debian.org/832455
Upstream fix:
https://github.com/ImageMagick/ImageMagick/commit/a54fe0e8600eaf3dc6fe717d3c0398001507f723
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1378790]
---
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1378790]
---
Statement:
This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5, 6, and 7.
Bugzilla
CVE-2015-7513 Kernel: kvm: divide by zero issue leads to DoS
bugzilla·2015-11-24·CVSS 6.5
CVE-2015-7513 [MEDIUM] CVE-2015-7513 Kernel: kvm: divide by zero issue leads to DoS
CVE-2015-7513 Kernel: kvm: divide by zero issue leads to DoS
Linux kernel built with the KVM virtualisation support(CONFIG_KVM) is vulnerable to a divide by zero issue. It occurs in the KVM module's Programmable Interval Timer(PIT) emulation, when PIT counters for channel 1 or 2 are set to zero(0) and a privileged user inside guest attempts to read those.
A privileged guest user with access to PIT I/O ports, could use this issue to crash the host kernel resulting in DoS.
Upstream patch:
-> https://git.kernel.org/linus/0185604c2d82c560dab2f2933a18f797e74ab5a8
Reference:
-> http://www.openwall.com/lists/oss-security/2016/01/07/2
-> http://wiki.osdev.org/Programmable_Interval_Timer
-> http://www.osdever.net/bkerndev/Docs/pit.htm
Discussion:
Created kernel tracking bugs for this issue:
http://www.openwall.com/lists/oss-security/2016/09/22/2http://www.securityfocus.com/bid/93121https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=832455https://bugzilla.redhat.com/show_bug.cgi?id=1378733https://github.com/ImageMagick/ImageMagick/commit/a54fe0e8600eaf3dc6fe717d3c0398001507f723http://www.openwall.com/lists/oss-security/2016/09/22/2http://www.securityfocus.com/bid/93121https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=832455https://bugzilla.redhat.com/show_bug.cgi?id=1378733https://github.com/ImageMagick/ImageMagick/commit/a54fe0e8600eaf3dc6fe717d3c0398001507f723
2017-04-20
Published