An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-756-1 | imagemagick security update |
Debian DSA |
DSA-3799-1 | imagemagick security update |
EUVD |
EUVD-2016-9546 | An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality. |
Ubuntu USN |
USN-3222-1 | ImageMagick vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: talos
Published:
Updated: 2024-08-06T02:27:41.290Z
Reserved: 2016-10-17T00:00:00
Link: CVE-2016-8707
No data.
Status : Deferred
Published: 2016-12-23T22:59:00.330
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-8707
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
EUVD
Ubuntu USN