Lucene search

K
redhatcveRedhat.comRH:CVE-2016-5688
HistoryJun 20, 2016 - 10:18 a.m.

CVE-2016-5688

2016-06-2010:18:41
redhat.com
access.redhat.com
17

0.008 Low

EPSS

Percentile

82.2%

The WPG parser in ImageMagick before 6.9.4-4 and 7.x before 7.0.1-5, when a memory limit is set, allows remote attackers to have unspecified impact via vectors related to the SetImageExtent return-value check, which trigger (1) a heap-based buffer overflow in the SetPixelIndex function or an invalid write operation in the (2) ScaleCharToQuantum or (3) SetPixelIndex functions.