9.8
CVE-2016-5691
- EPSS 5.45%
- Veröffentlicht 13.12.2016 15:59:04
- Zuletzt bearbeitet 06.05.2026 22:30:45
- Erkennungen
The DCM reader in ImageMagick before 6.9.4-5 and 7.x before 7.0.1-7 allows remote attackers to have unspecified impact by leveraging lack of validation of (1) pixel.red, (2) pixel.green, and (3) pixel.blue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Imagemagick ≫ Imagemagick Version <= 6.9.4-4
Imagemagick ≫ Imagemagick Version 7.0.1-0
Imagemagick ≫ Imagemagick Version 7.0.1-1
Imagemagick ≫ Imagemagick Version 7.0.1-2
Imagemagick ≫ Imagemagick Version 7.0.1-3
Imagemagick ≫ Imagemagick Version 7.0.1-4
Imagemagick ≫ Imagemagick Version 7.0.1-5
Imagemagick ≫ Imagemagick Version 7.0.1-6
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.45% | 0.917 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html
http://www.openwall.com/lists/oss-security/2016/06/14/5
http://www.openwall.com/lists/oss-security/2016/06/17/3
http://www.securityfocus.com/bid/91283
https://blog.fuzzing-project.org/46-Various-invalid-memory-reads-in-ImageMagick-WPG%2C-DDS%2C-DCM.html
https://github.com/ImageMagick/ImageMagick/blob/6.9.4-5/ChangeLog
https://github.com/ImageMagick/ImageMagick/blob/7.0.1-7/ChangeLog
https://github.com/ImageMagick/ImageMagick/commit/5511ef530576ed18fd636baa3bb4eda3d667665d