CVE-2016-8707
Publication date 23 December 2016
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
An exploitable out of bounds write exists in the handling of compressed TIFF images in ImageMagicks's convert utility. A crafted TIFF document can lead to an out of bounds write which in particular circumstances could be leveraged into remote code execution. The vulnerability can be triggered through any user controlled TIFF that is handled by this functionality.
Status
Package | Ubuntu Release | Status |
---|---|---|
imagemagick | ||
16.04 LTS xenial |
Fixed 8:6.8.9.9-7ubuntu5.5
|
|
14.04 LTS trusty |
Fixed 8:6.7.7.10-6ubuntu3.5
|
|
Notes
mdeslaur
This is 0175-Fix-possible-buffer-overflow-when-writing-compressed.patch and 0176-Fix-possible-buffer-overflow-when-writing-compressed.patch
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.8 · High |
Attack vector | Local |
Attack complexity | Low |
Privileges required | None |
User interaction | Required |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-3222-1
- ImageMagick vulnerabilities
- 8 March 2017