CVE-2016-7539
published 2017-07-25CVE-2016-7539: Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
PriorityP433high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
EPSS
4.87%
91.1th percentile
Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.9.6.2+dfsg-2 (bookworm) | imagemagick 8:6.9.6.2+dfsg-2 (bookworm) |
| imagemagick | imagemagick | <= 6.9.9-3 | — |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.6.2+dfsg-2 | 8:6.9.6.2+dfsg-2 |
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2016-11-21
CVE-2014-8354 ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled certain malformed
image files. If a user or automated system using ImageMagick were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service or possibly execute code with the privileges of
the user invoking the program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ImageMagick: potential DOS by not releasing memory
vendor_redhat·2016-01-07·CVSS 7.5
CVE-2016-7539 [HIGH] CWE-400 ImageMagick: potential DOS by not releasing memory
ImageMagick: potential DOS by not releasing memory
Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 6) - Will not fix
Package: ImageMagick (Red Hat Enterprise Linux 7) - Will not fix
Package: ImageMagick (Red Hat OpenShift Enterprise 2) - Will not fix
Debian
CVE-2016-7539: imagemagick - Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attack...
vendor_debian·2016·CVSS 7.5
CVE-2016-7539 [HIGH] CVE-2016-7539: imagemagick - Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attack...
Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 8:6.9.6.2+dfsg-2)
bullseye: resolved (fixed in 8:6.9.6.2+dfsg-2)
forky: resolved (fixed in 8:6.9.6.2+dfsg-2)
sid: resolved (fixed in 8:6.9.6.2+dfsg-2)
trixie: resolved (fixed in 8:6.9.6.2+dfsg-2)
GHSA
GHSA-f46j-2g68-jrmx: Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified
ghsa_unreviewed·2022-05-17
CVE-2016-7539 [HIGH] GHSA-f46j-2g68-jrmx: Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified
Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
OSV
CVE-2016-7539: Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified
osv·2017-07-25·CVSS 7.5
CVE-2016-7539 [HIGH] CVE-2016-7539: Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified
Memory leak in AcquireVirtualMemory in ImageMagick before 7 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9907 CVE-2015-8957 CVE-2015-8958 CVE-2015-8959 CVE-2016-6823 CVE-2016-7101 CVE-2016-7513 CVE-2016-7514 CVE-2016-7515 CVE-2016-7516 CVE-2016-7517 CVE-2016-7518 CVE-2016-7519 CVE-2016-7520 CVE-
bugzilla·2016-09-23·CVSS 6.5
CVE-2014-9907 [MEDIUM] CVE-2014-9907 CVE-2015-8957 CVE-2015-8958 CVE-2015-8959 CVE-2016-6823 CVE-2016-7101 CVE-2016-7513 CVE-2016-7514 CVE-2016-7515 CVE-2016-7516 CVE-2016-7517 CVE-2016-7518 CVE-2016-7519 CVE-2016-7520 CVE-
CVE-2014-9907 CVE-2015-8957 CVE-2015-8958 CVE-2015-8959 CVE-2016-6823 CVE-2016-7101 CVE-2016-7513 CVE-2016-7514 CVE-2016-7515 CVE-2016-7516 CVE-2016-7517 CVE-2016-7518 CVE-2016-7519 CVE-2016-7520 CVE-2016-7521 ... ImageMagick: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevan
Bugzilla
CVE-2016-7539 ImageMagick: potential DOS by not releasing memory
bugzilla·2016-09-23·CVSS 7.5
CVE-2016-7539 [HIGH] CVE-2016-7539 ImageMagick: potential DOS by not releasing memory
CVE-2016-7539 ImageMagick: potential DOS by not releasing memory
Bug report(s):
http://www.imagemagick.org/discourse-server/viewtopic.php?f=2&t=28946
https://bugs.debian.org/833101
Upstream patch(es):
https://github.com/ImageMagick/ImageMagick/commit/4e81ce8b07219c69a9aeccb0f7f7b927ca6db74c
CVE assignment:
http://seclists.org/oss-sec/2016/q3/590
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1378790]
---
Errors within the cache handling could lead to performance issues or temporary files not being removed correctly. This could result in a higher usage of resources than necessary, but ultimately is not that much of an issue.
http://www.imagemagick.org/discourse-server/viewtopic.php?f=2&t=28946http://www.openwall.com/lists/oss-security/2016/09/22/2http://www.securityfocus.com/bid/93232https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=833101https://bugzilla.redhat.com/show_bug.cgi?id=1378776https://github.com/ImageMagick/ImageMagick/commit/4e81ce8b07219c69a9aeccb0f7f7b927ca6db74chttp://www.imagemagick.org/discourse-server/viewtopic.php?f=2&t=28946http://www.openwall.com/lists/oss-security/2016/09/22/2http://www.securityfocus.com/bid/93232https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=833101https://bugzilla.redhat.com/show_bug.cgi?id=1378776https://github.com/ImageMagick/ImageMagick/commit/4e81ce8b07219c69a9aeccb0f7f7b927ca6db74c
2017-07-25
Published