Vulnerability Description
coders/rgf.c in ImageMagick before 6.9.4-10 allows remote attackers to cause a denial of service (assertion failure) by converting an image to rgf format.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Imagemagick | Imagemagick | <= 6.9.4-9 |
Related Weaknesses (CWE)
References
- http://www.openwall.com/lists/oss-security/2016/09/22/2Mailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/93228Third Party AdvisoryVDB Entry
- https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1594060Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1378777Issue TrackingPatchThird Party Advisory
- https://github.com/ImageMagick/ImageMagick/commit/a0108a892f9ea3c2bb1e7a49b7d713Patch
- https://github.com/ImageMagick/ImageMagick/pull/223Issue TrackingPatchVendor Advisory
- http://www.openwall.com/lists/oss-security/2016/09/22/2Mailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/93228Third Party AdvisoryVDB Entry
- https://bugs.launchpad.net/ubuntu/+source/imagemagick/+bug/1594060Issue TrackingThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1378777Issue TrackingPatchThird Party Advisory
- https://github.com/ImageMagick/ImageMagick/commit/a0108a892f9ea3c2bb1e7a49b7d713Patch
- https://github.com/ImageMagick/ImageMagick/pull/223Issue TrackingPatchVendor Advisory
FAQ
What is CVE-2016-7540?
CVE-2016-7540 is a vulnerability with a CVSS score of 6.5 (MEDIUM). coders/rgf.c in ImageMagick before 6.9.4-10 allows remote attackers to cause a denial of service (assertion failure) by converting an image to rgf format.
How severe is CVE-2016-7540?
CVE-2016-7540 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2016-7540?
Check the references section above for vendor advisories and patch information. Affected products include: Imagemagick Imagemagick.