The SGI coder in ImageMagick before 7.0.2-10 allows remote attackers to cause a denial of service (out-of-bounds read) via a large row value in an sgi file.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-7101.json"
[
{
"id": "CVE-2016-7101-3e567658",
"source": "https://github.com/imagemagick/imagemagick/commit/8f8959033e4e59418d6506b345829af1f7a71127",
"target": {
"file": "coders/sgi.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"266204678405030727031496199494922106984",
"125736710075316659223917567180506240214",
"308455996441006417918026330732510489724",
"234967207698881659759933109382306508720",
"259812506292589860944075292333268079035",
"9794155586617700425172112840808582007",
"318078639804068450753963484756209832325",
"46885024942554281535203521320653378315",
"115669080092853842785472113769210057627",
"274126974349213375231627088300023248002",
"81969222224102601993321910037862741463",
"335962404136367631274071449066358605153",
"193169363481484722863787417111129117411",
"116387040711806819493817192078915962596",
"305374949747053751924033898562000872936"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
},
{
"id": "CVE-2016-7101-43ae43cc",
"source": "https://github.com/imagemagick/imagemagick/commit/7afcf9f71043df15508e46f079387bd4689a738d",
"target": {
"file": "coders/sgi.c",
"function": "ReadSGIImage"
},
"digest": {
"function_hash": "38992979835926582678353836717524664850",
"length": 11108.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
},
{
"id": "CVE-2016-7101-4db2fb23",
"source": "https://github.com/imagemagick/imagemagick/commit/7afcf9f71043df15508e46f079387bd4689a738d",
"target": {
"file": "coders/sgi.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"175738667582951687709934378911256453683",
"173870332777356733597540604599799727409",
"109051879306058611738241749710437944719",
"24499431317792828616637206672947119917",
"119235688060635533120094398494704443561",
"94076028067114905915555189509555766357",
"318604369223038471143800125259557374019",
"267892749823546944089710570774029745235",
"234059992580300943213135794320117750814",
"30947904900441035358072037530787739733"
]
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line"
},
{
"id": "CVE-2016-7101-797f1d8c",
"source": "https://github.com/imagemagick/imagemagick/commit/8f8959033e4e59418d6506b345829af1f7a71127",
"target": {
"file": "coders/sgi.c",
"function": "ReadSGIImage"
},
"digest": {
"function_hash": "131947027645671638522443821328189428309",
"length": 11204.0
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function"
}
]