CVE-2016-7515
published 2017-04-19CVE-2016-7515: The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the…
PriorityP427medium6.5CVSS 3.1
AVNACLPRNUIRSUCNINAH
EPSS
2.92%
85.6th percentile
The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the number of pixels.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.9.6.2+dfsg-2 (bookworm) | imagemagick 8:6.9.6.2+dfsg-2 (bookworm) |
| imagemagick | imagemagick | < 6.9.4-0 | 6.9.4-0 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2016-11-21
CVE-2014-8354 ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled certain malformed
image files. If a user or automated system using ImageMagick were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service or possibly execute code with the privileges of
the user invoking the program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ImageMagick: rle file handling OOB read
vendor_redhat·2016-01-13·CVSS 6.5
CVE-2016-7515 [MEDIUM] CWE-125 ImageMagick: rle file handling OOB read
ImageMagick: rle file handling OOB read
The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the number of pixels.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Will not fix
Package: ImageMagick (Red Hat Enterprise Linux 6) - Will not fix
Package: ImageMagick (Red Hat Enterprise Linux 7) - Will not fix
Package: ImageMagick (Red Hat OpenShift Enterprise 2) - Affected
Debian
CVE-2016-7515: imagemagick - The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers...
vendor_debian·2016·CVSS 6.5
CVE-2016-7515 [MEDIUM] CVE-2016-7515: imagemagick - The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers...
The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the number of pixels.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6.2+dfsg-2)
sid: resolved (fixed in 8:6.9.6.2+dfsg-2)
trixie: resolved (fixed in 8:6.9.6.2+dfsg-2)
GHSA
GHSA-5668-x27c-mqff: The ReadRLEImage function in coders/rle
ghsa_unreviewed·2022-05-17
CVE-2016-7515 [MEDIUM] CWE-125 GHSA-5668-x27c-mqff: The ReadRLEImage function in coders/rle
The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the number of pixels.
OSV
CVE-2016-7515: The ReadRLEImage function in coders/rle
osv·2017-04-19·CVSS 6.5
CVE-2016-7515 [MEDIUM] CVE-2016-7515: The ReadRLEImage function in coders/rle
The ReadRLEImage function in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to the number of pixels.
OSV
linux-lts-wily vulnerabilities
osv·2016-05-09·CVSS 4.6
CVE-2015-7515 linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
USN-2971-1 fixed vulnerabilities in the Linux kernel for Ubuntu 15.10.
This update provides the corresponding updates for the Linux Hardware
Enablement (HWE) kernel from Ubuntu 15.10 for Ubuntu 14.04 LTS.
Ralf Spenneberg discovered that the Aiptek Tablet USB device driver in the
Linux kernel did not properly validate the endpoints reported by the
device. An attacker with physical access could cause a denial of service
(system crash). (CVE-2015-7515)
Zach Riggle discovered that the Linux kernel's list poison feature did not
take into account the mmap_min_addr value. A local attacker could use this
to bypass the kernel's poison-pointer protection mechanism while attempting
to exploit an existing kernel vulnerability. (CVE-2016-0821)
Ralf Spenneberg discover
No detection rules found.
Bugzilla
CVE-2014-9907 CVE-2015-8957 CVE-2015-8958 CVE-2015-8959 CVE-2016-6823 CVE-2016-7101 CVE-2016-7513 CVE-2016-7514 CVE-2016-7515 CVE-2016-7516 CVE-2016-7517 CVE-2016-7518 CVE-2016-7519 CVE-2016-7520 CVE-
bugzilla·2016-09-23·CVSS 6.5
CVE-2014-9907 [MEDIUM] CVE-2014-9907 CVE-2015-8957 CVE-2015-8958 CVE-2015-8959 CVE-2016-6823 CVE-2016-7101 CVE-2016-7513 CVE-2016-7514 CVE-2016-7515 CVE-2016-7516 CVE-2016-7517 CVE-2016-7518 CVE-2016-7519 CVE-2016-7520 CVE-
CVE-2014-9907 CVE-2015-8957 CVE-2015-8958 CVE-2015-8959 CVE-2016-6823 CVE-2016-7101 CVE-2016-7513 CVE-2016-7514 CVE-2016-7515 CVE-2016-7516 CVE-2016-7517 CVE-2016-7518 CVE-2016-7519 CVE-2016-7520 CVE-2016-7521 ... ImageMagick: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevan
Bugzilla
CVE-2016-7515 ImageMagick: rle file handling OOB read
bugzilla·2016-09-23·CVSS 6.5
CVE-2016-7515 [MEDIUM] CVE-2016-7515 ImageMagick: rle file handling OOB read
CVE-2016-7515 ImageMagick: rle file handling OOB read
Bug report(s):
https://github.com/ImageMagick/ImageMagick/issues/82
https://bugs.launchpad.net/bugs/1533445
https://bugs.debian.org/832461
Upstream patch(es):
https://github.com/ImageMagick/ImageMagick/commit/2ad6d33493750a28a5a655d319a8e0b16c392de1
CVE assignment:
http://seclists.org/oss-sec/2016/q3/590
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1378790]
---
Statement:
Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
http://www.openwall.com/lists/oss-security/2016/09/22/2http://www.securityfocus.com/bid/93120https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1533445https://bugzilla.redhat.com/show_bug.cgi?id=1378741https://github.com/ImageMagick/ImageMagick/commit/2ad6d33493750a28a5a655d319a8e0b16c392de1https://github.com/ImageMagick/ImageMagick/issues/82http://www.openwall.com/lists/oss-security/2016/09/22/2http://www.securityfocus.com/bid/93120https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1533445https://bugzilla.redhat.com/show_bug.cgi?id=1378741https://github.com/ImageMagick/ImageMagick/commit/2ad6d33493750a28a5a655d319a8e0b16c392de1https://github.com/ImageMagick/ImageMagick/issues/82
2017-04-19
Published