Lucene search

K
f5F5F5:K30403302
HistoryNov 21, 2016 - 12:00 a.m.

K30403302 : ImageMagick vulnerabilities CVE-2015-8895 and CVE-2015-8896

2016-11-2100:00:00
my.f5.com
18

7.3 High

AI Score

Confidence

High

0.016 Low

EPSS

Percentile

87.6%

Security Advisory Description

Integer overflow in coders/icon.c in ImageMagick 6.9.1-3 and later allows remote attackers to cause a denial of service (application crash) via a crafted length value, which triggers a buffer overflow.

Integer truncation issue in coders/pict.c in ImageMagick before 7.0.5-0 allows remote attackers to cause a denial of service (application crash) via a crafted .pict file.
Impact
BIG-IP systems that use a WebAcceleration profile configured with the Image Optimization settings (BIG-IP AAM and BIG-IP WebAccelerator) are vulnerable to this issue. An attacker, using specially crafted Microsoft ICON (ICON) or Apple QuickDraw (PICT) image format files, could cause memory corruption and, potentially, execution of arbitrary code with restricted user privileges, denial of service (DoS), or application restart.