CVE-2016-10049

Source
https://cve.org/CVERecord?id=CVE-2016-10049
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10049.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-10049
Downstream
Related
Published
2017-03-23T17:59:00.390Z
Modified
2026-01-30T14:37:08.157899Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick before 6.9.4-4 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted RLE file.

References

Affected packages

Git / github.com/imagemagick/imagemagick

Affected ranges

Type
GIT
Repo
https://github.com/imagemagick/imagemagick
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

7.*
7.0.1-0
7.0.1-1
7.0.1-2
7.0.1-3
7.0.1-4

Database specific

vanir_signatures
[
    {
        "id": "CVE-2016-10049-061255cf",
        "target": {
            "file": "coders/rle.c"
        },
        "digest": {
            "line_hashes": [
                "15085698245396628979736252668829938793",
                "207593829335744966479485846325957567674",
                "205730496597199750897337113208774315595",
                "1625854575163316370524320667962756903",
                "209238465439521243691342055796927148967",
                "315930026504774688844713364405651882690",
                "257496872548704593883252145595791765473"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/imagemagick/imagemagick/commit/13db820f5e24cd993ee554e99377fea02a904e18"
    },
    {
        "id": "CVE-2016-10049-8143401b",
        "target": {
            "file": "coders/rle.c"
        },
        "digest": {
            "line_hashes": [
                "15085698245396628979736252668829938793",
                "207593829335744966479485846325957567674",
                "205730496597199750897337113208774315595",
                "1625854575163316370524320667962756903",
                "209238465439521243691342055796927148967",
                "315930026504774688844713364405651882690",
                "257496872548704593883252145595791765473"
            ],
            "threshold": 0.9
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Line",
        "source": "https://github.com/imagemagick/imagemagick/commit/3e9165285eda6e1bb71172031d3048b51bb443a4"
    },
    {
        "id": "CVE-2016-10049-92d9c5c1",
        "target": {
            "file": "coders/rle.c",
            "function": "ReadRLEImage"
        },
        "digest": {
            "length": 10666.0,
            "function_hash": "249481700803844261421136940074108375902"
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Function",
        "source": "https://github.com/imagemagick/imagemagick/commit/3e9165285eda6e1bb71172031d3048b51bb443a4"
    },
    {
        "id": "CVE-2016-10049-b5a57b0d",
        "target": {
            "file": "coders/rle.c",
            "function": "ReadRLEImage"
        },
        "digest": {
            "length": 10804.0,
            "function_hash": "25849057458396076997342902357546017727"
        },
        "deprecated": false,
        "signature_version": "v1",
        "signature_type": "Function",
        "source": "https://github.com/imagemagick/imagemagick/commit/13db820f5e24cd993ee554e99377fea02a904e18"
    }
]
source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10049.json"

Git / github.com/imagemagick/imagemagick6

Affected ranges

Type
GIT
Repo
https://github.com/imagemagick/imagemagick6
Events
Introduced
0 Unknown introduced commit / All previous commits are affected

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-10049.json"