CVE-2016-8678Out-of-bounds Read in Imagemagick

Severity
5.5MEDIUMNVD
EPSS
0.2%
top 56.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateMay 17

Description

The IsPixelMonochrome function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.0 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted file. NOTE: the vendor says "This is a Q64 issue and we do not support Q64."

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5m5c-j6ww-9gpm: The IsPixelMonochrome function in MagickCore/pixel-accessor2022-05-17
OSV
CVE-2016-8678: The IsPixelMonochrome function in MagickCore/pixel-accessor2017-02-15

📋Vendor Advisories

2
Red Hat
ImageMagick: Heap-buffer overflow in IsPixelMonochrome2016-10-07
Debian
CVE-2016-8678: imagemagick - The IsPixelMonochrome function in MagickCore/pixel-accessor.h in ImageMagick 7.0...2016

💬Community

2
Bugzilla
CVE-2016-8678 ImageMagick: Heap-buffer overflow in IsPixelMonochrome2016-10-17
Bugzilla
CVE-2016-7799 CVE-2016-7906 CVE-2016-8677 CVE-2016-8678 CVE-2016-8862 CVE-2016-8866 CVE-2016-9298 ImageMagick: various flaws [fedora-all]2016-10-03