Integer overflow in the BMP coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (crash) via crafted height and width values, which triggers an out-of-bounds write.
[
{
"signature_type": "Function",
"source": "https://github.com/imagemagick/imagemagick/commit/104b6c96a4d7cd159f234a8f8fa1b4649b1d7286",
"target": {
"file": "coders/psd.c",
"function": "WritePSDImage"
},
"id": "CVE-2016-6823-6e2077b7",
"signature_version": "v1",
"digest": {
"function_hash": "233824663533578799883944741873460280200",
"length": 9732.0
},
"deprecated": false
},
{
"signature_type": "Function",
"source": "https://github.com/imagemagick/imagemagick/commit/104b6c96a4d7cd159f234a8f8fa1b4649b1d7286",
"target": {
"file": "coders/psd.c",
"function": "FilterAdditionalLayerInformation"
},
"id": "CVE-2016-6823-a11d4e55",
"signature_version": "v1",
"digest": {
"function_hash": "129518849084965542227393714367609967839",
"length": 1810.0
},
"deprecated": false
},
{
"signature_type": "Line",
"source": "https://github.com/imagemagick/imagemagick/commit/104b6c96a4d7cd159f234a8f8fa1b4649b1d7286",
"target": {
"file": "coders/psd.c"
},
"id": "CVE-2016-6823-c8cfb57f",
"signature_version": "v1",
"digest": {
"threshold": 0.9,
"line_hashes": [
"108740126882545814851533735595465736822",
"48477567520902389236647671138370929630",
"87977518246777124720835573222756406809",
"326475873969871574180186612361008149091",
"103316115861786808335111923209966370780",
"328181468267352931963705897837823121811",
"156806815285268351483048121514396599840",
"282853779392576571124339293828972945725",
"312083330872765293319986429520062410420",
"192103501246992342805196797283805010345",
"108950214869754331967832519788943577408",
"35292478060111696458058930589778156425",
"185792689403760769672262205046227631005",
"59097276997680189510529763139163968628",
"237934478085821480177959881169460742626",
"196352857121978090287577182543906081952",
"49653345742379819664969521811633097205",
"31491154282409138535382876070113104871",
"218661088709509303266055304047316721918",
"20253547151499278016004694190735579378"
]
},
"deprecated": false
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-6823.json"