CVE-2016-7799
Moderate
CVE-2016-7799
MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
Exploit probability
3.6%
Published
January 18, 2017
Required by
Not available
Last source change
August 7, 2026
02 / AFFECTED SOFTWARE
Affected packages
46 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
CVE-2016-7799
View original source
MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
05 / REFERENCES
Further evidence
- http://www.debian.org/security/2016/dsa-3726
- http://www.openwall.com/lists/oss-security/2016/10/01/4
- http://www.openwall.com/lists/oss-security/2016/10/01/6
- http://www.securityfocus.com/bid/93264
- https://github.com/ImageMagick/ImageMagick/commit/a7bb158b7bedd1449a34432feb3a67c8f1873bfa
- https://github.com/ImageMagick/ImageMagick/issues/280
- https://security.gentoo.org/glsa/201611-21