Vulnerability Description
MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Imagemagick | Imagemagick | < 6.9.4-10 |
| Oracle | Solaris | 10 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2016/06/23/1Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/06/25/3ExploitMailing ListThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlThird Party Advisory
- http://www.securityfocus.com/bid/91394ExploitThird Party AdvisoryVDB Entry
- https://github.com/ImageMagick/ImageMagick/commit/d8ab7f046587f2e9f734b687ba7e6ePatchThird Party Advisory
- https://github.com/ImageMagick/ImageMagick/commits/7.0.2-1PatchThird Party Advisory
- https://security.gentoo.org/glsa/201611-21Third Party Advisory
- http://www.openwall.com/lists/oss-security/2016/06/23/1Mailing ListPatchThird Party Advisory
- http://www.openwall.com/lists/oss-security/2016/06/25/3ExploitMailing ListThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.htmlThird Party Advisory
- http://www.securityfocus.com/bid/91394ExploitThird Party AdvisoryVDB Entry
- https://github.com/ImageMagick/ImageMagick/commit/d8ab7f046587f2e9f734b687ba7e6ePatchThird Party Advisory
- https://github.com/ImageMagick/ImageMagick/commits/7.0.2-1PatchThird Party Advisory
- https://security.gentoo.org/glsa/201611-21Third Party Advisory
FAQ
What is CVE-2016-5842?
CVE-2016-5842 is a vulnerability with a CVSS score of 7.5 (HIGH). MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.
How severe is CVE-2016-5842?
CVE-2016-5842 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-5842?
Check the references section above for vendor advisories and patch information. Affected products include: Imagemagick Imagemagick, Oracle Solaris.