CVE-2016-8682Out-of-bounds Read in Graphicsmagick

CWE-125Out-of-bounds Read7 documents5 sources
Severity
7.5HIGHNVD
EPSS
1.8%
top 17.24%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 15
Latest updateMay 14

Description

The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted SCT header.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

debiandebian/graphicsmagick< graphicsmagick 1.3.25-5 (bookworm)
Debiangraphicsmagick/graphicsmagick< 1.3.25-5+3

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-pqjj-r7v2-357p: The ReadSCTImage function in coders/sct2022-05-14
OSV
CVE-2016-8682: The ReadSCTImage function in coders/sct2017-02-15

📋Vendor Advisories

1
Debian
CVE-2016-8682: graphicsmagick - The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote...2016

💬Community

3
Bugzilla
CVE-2016-8682 CVE-2016-8683 CVE-2016-8684 GraphicsMagick: Multiple security issues2016-10-17
Bugzilla
CVE-2016-7800 CVE-2016-7996 CVE-2016-7997 CVE-2016-8682 CVE-2016-8683 CVE-2016-8684 CVE-2016-9830 GraphicsMagick: various flaws [epel-all]2016-10-10
Bugzilla
CVE-2016-7800 CVE-2016-7996 CVE-2016-7997 CVE-2016-8682 CVE-2016-8683 CVE-2016-8684 CVE-2016-9830 GraphicsMagick: various flaws [fedora-all]2016-10-10