~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
Candidate: CVE-2016-10046
PublicDate: 2017-03-23
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10046
 http://www.openwall.com/lists/oss-security/2016/12/20/3
Description:
 Heap-based buffer overflow in the DrawImage function in magick/draw.c in
 ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of
 service (application crash) via a crafted image file.
Ubuntu-Description:
Notes:
 mdeslaur> This is 0140-Prevent-buffer-overflow-in-draw.c.patch
Bugs:
 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=833730
Priority: medium
Discovered-by: Max Thrane
Assigned-to:

Patches_imagemagick:
 upstream: https://github.com/ImageMagick/ImageMagick/commit/989f9f88ea6db09b99d25586e912c921c0da8d3f
upstream_imagemagick: released (8:6.9.6.2+dfsg-2)
precise_imagemagick: released (8:6.6.9.7-5ubuntu3.5)
trusty_imagemagick: released (8:6.7.7.10-6ubuntu3.2)
vivid/stable-phone-overlay_imagemagick: DNE
vivid/ubuntu-core_imagemagick: DNE
xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.2)
yakkety_imagemagick: released (8:6.8.9.9-7ubuntu8.1)
devel_imagemagick: not-affected (8:6.9.6.6+dfsg-1ubuntu3)