CVE-2016-6823

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
18/01/2017
Last modified:
20/04/2025

Description

Integer overflow in the BMP coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (crash) via crafted height and width values, which triggers an out-of-bounds write.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* 6.9.10-50 (excluding)
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* 7.0.0-0 (including) 7.0.2-10 (excluding)