The SGI coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large row value in an sgi file.
[
{
"digest": {
"line_hashes": [
"266204678405030727031496199494922106984",
"125736710075316659223917567180506240214",
"308455996441006417918026330732510489724",
"234967207698881659759933109382306508720",
"259812506292589860944075292333268079035",
"9794155586617700425172112840808582007",
"318078639804068450753963484756209832325",
"46885024942554281535203521320653378315",
"115669080092853842785472113769210057627",
"274126974349213375231627088300023248002",
"81969222224102601993321910037862741463",
"335962404136367631274071449066358605153",
"193169363481484722863787417111129117411",
"116387040711806819493817192078915962596",
"305374949747053751924033898562000872936"
],
"threshold": 0.9
},
"id": "CVE-2016-7101-3e567658",
"signature_version": "v1",
"target": {
"file": "coders/sgi.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/8f8959033e4e59418d6506b345829af1f7a71127",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"function_hash": "38992979835926582678353836717524664850",
"length": 11108.0
},
"id": "CVE-2016-7101-43ae43cc",
"signature_version": "v1",
"target": {
"file": "coders/sgi.c",
"function": "ReadSGIImage"
},
"source": "https://github.com/imagemagick/imagemagick/commit/7afcf9f71043df15508e46f079387bd4689a738d",
"deprecated": false,
"signature_type": "Function"
},
{
"digest": {
"line_hashes": [
"175738667582951687709934378911256453683",
"173870332777356733597540604599799727409",
"109051879306058611738241749710437944719",
"24499431317792828616637206672947119917",
"119235688060635533120094398494704443561",
"94076028067114905915555189509555766357",
"318604369223038471143800125259557374019",
"267892749823546944089710570774029745235",
"234059992580300943213135794320117750814",
"30947904900441035358072037530787739733"
],
"threshold": 0.9
},
"id": "CVE-2016-7101-4db2fb23",
"signature_version": "v1",
"target": {
"file": "coders/sgi.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/7afcf9f71043df15508e46f079387bd4689a738d",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"function_hash": "131947027645671638522443821328189428309",
"length": 11204.0
},
"id": "CVE-2016-7101-797f1d8c",
"signature_version": "v1",
"target": {
"file": "coders/sgi.c",
"function": "ReadSGIImage"
},
"source": "https://github.com/imagemagick/imagemagick/commit/8f8959033e4e59418d6506b345829af1f7a71127",
"deprecated": false,
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-7101.json"
[
{
"digest": {
"line_hashes": [
"108740126882545814851533735595465736822",
"48477567520902389236647671138370929630",
"87977518246777124720835573222756406809",
"84753881553476775258891330976462556223",
"155609111829766798641137799421712012612",
"255341032439269261320635827463233094372",
"184847602632045208793430889847669681440",
"312083330872765293319986429520062410420",
"192103501246992342805196797283805010345",
"108950214869754331967832519788943577408",
"35292478060111696458058930589778156425",
"185792689403760769672262205046227631005",
"59097276997680189510529763139163968628",
"237934478085821480177959881169460742626",
"196352857121978090287577182543906081952",
"271655001391509804335411098799191708068",
"68914122621374857408525954426970417130",
"313902962427810150903660941337562869610",
"275254203105307134258303080212656236648",
"24574565019827027245956094580362128240",
"245147871992941663000817129628397723463",
"74485250202162378269615953882358810863",
"90830639591579514837463664665496985063"
],
"threshold": 0.9
},
"id": "CVE-2016-7101-730d81f7",
"signature_version": "v1",
"target": {
"file": "coders/psd.c"
},
"source": "https://github.com/imagemagick/imagemagick6/commit/a1f20bada73d7bc3caeb0848cbfb8f2e47cdeb82",
"deprecated": false,
"signature_type": "Line"
},
{
"digest": {
"function_hash": "149391582554956405594455371198657664568",
"length": 1786.0
},
"id": "CVE-2016-7101-7e3a5c8a",
"signature_version": "v1",
"target": {
"file": "coders/psd.c",
"function": "FilterAdditionalLayerInformation"
},
"source": "https://github.com/imagemagick/imagemagick6/commit/a1f20bada73d7bc3caeb0848cbfb8f2e47cdeb82",
"deprecated": false,
"signature_type": "Function"
},
{
"digest": {
"function_hash": "43342500214236906679621929440654510826",
"length": 9477.0
},
"id": "CVE-2016-7101-a4c6878c",
"signature_version": "v1",
"target": {
"file": "coders/psd.c",
"function": "WritePSDImage"
},
"source": "https://github.com/imagemagick/imagemagick6/commit/a1f20bada73d7bc3caeb0848cbfb8f2e47cdeb82",
"deprecated": false,
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-7101.json"