CVE-2016-4563

Description

The TraceStrokePolygon function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 mishandles the relationship between the BezierQuantum value and certain strokes data, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.

Risk Information

Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.771

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Imagemagic (x64) 7.0.1Windows
Multiple Vulnerabilities are affected in Imagemagic 7.0.1Windows
Multiple Vulnerabilities are affected in ImageMagick 7.0.1Windows
imagemagick security update(DSA-3652-1) imagemagick_6.8.9.9-5+deb8u4_i386.debLinux
imagemagick security update(DSA-3652-1) imagemagick_6.8.9.9-5+deb8u4_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234