CVE-2016-8678

Source
https://nvd.nist.gov/vuln/detail/CVE-2016-8678
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2016-8678.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2016-8678
Related
Published
2017-02-15T21:59:00Z
Modified
2025-01-08T04:13:28.358385Z
Severity
  • 5.5 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

The IsPixelMonochrome function in MagickCore/pixel-accessor.h in ImageMagick 7.0.3.0 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted file. NOTE: the vendor says "This is a Q64 issue and we do not support Q64."

References

Affected packages

Debian:11 / imagemagick

Package

Name
imagemagick
Purl
pkg:deb/debian/imagemagick?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8:6.*

8:6.9.11.60+dfsg-1.3
8:6.9.11.60+dfsg-1.3+deb11u1
8:6.9.11.60+dfsg-1.3+deb11u2
8:6.9.11.60+dfsg-1.3+deb11u3
8:6.9.11.60+dfsg-1.3+deb11u4
8:6.9.11.60+dfsg-1.4
8:6.9.11.60+dfsg-1.5
8:6.9.11.60+dfsg-1.6
8:6.9.12.20+dfsg1-1
8:6.9.12.20+dfsg1-1.1
8:6.9.12.20+dfsg1-1.2
8:6.9.12.98+dfsg1-1
8:6.9.12.98+dfsg1-2
8:6.9.12.98+dfsg1-3
8:6.9.12.98+dfsg1-4
8:6.9.12.98+dfsg1-5
8:6.9.12.98+dfsg1-5.1~exp1
8:6.9.12.98+dfsg1-5.1
8:6.9.12.98+dfsg1-5.2
8:6.9.13.12+dfsg1-1

8:7.*

8:7.1.1.33+dfsg1-1
8:7.1.1.33+dfsg1-2
8:7.1.1.39+dfsg1-1
8:7.1.1.39+dfsg1-2
8:7.1.1.39+dfsg1-3
8:7.1.1.43+dfsg1-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / imagemagick

Package

Name
imagemagick
Purl
pkg:deb/debian/imagemagick?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8:6.*

8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.12.20+dfsg1-1
8:6.9.12.20+dfsg1-1.1
8:6.9.12.20+dfsg1-1.2
8:6.9.12.98+dfsg1-1
8:6.9.12.98+dfsg1-2
8:6.9.12.98+dfsg1-3
8:6.9.12.98+dfsg1-4
8:6.9.12.98+dfsg1-5
8:6.9.12.98+dfsg1-5.1~exp1
8:6.9.12.98+dfsg1-5.1
8:6.9.12.98+dfsg1-5.2
8:6.9.13.12+dfsg1-1

8:7.*

8:7.1.1.33+dfsg1-1
8:7.1.1.33+dfsg1-2
8:7.1.1.39+dfsg1-1
8:7.1.1.39+dfsg1-2
8:7.1.1.39+dfsg1-3
8:7.1.1.43+dfsg1-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / imagemagick

Package

Name
imagemagick
Purl
pkg:deb/debian/imagemagick?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8:6.*

8:6.9.11.60+dfsg-1.6
8:6.9.12.20+dfsg1-1
8:6.9.12.20+dfsg1-1.1
8:6.9.12.20+dfsg1-1.2
8:6.9.12.98+dfsg1-1
8:6.9.12.98+dfsg1-2
8:6.9.12.98+dfsg1-3
8:6.9.12.98+dfsg1-4
8:6.9.12.98+dfsg1-5
8:6.9.12.98+dfsg1-5.1~exp1
8:6.9.12.98+dfsg1-5.1
8:6.9.12.98+dfsg1-5.2
8:6.9.13.12+dfsg1-1

8:7.*

8:7.1.1.33+dfsg1-1
8:7.1.1.33+dfsg1-2
8:7.1.1.39+dfsg1-1
8:7.1.1.39+dfsg1-2
8:7.1.1.39+dfsg1-3
8:7.1.1.43+dfsg1-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Git / github.com/imagemagick/imagemagick

Affected ranges

Type
GIT
Repo
https://github.com/imagemagick/imagemagick
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

7.*

7.0.1-0
7.0.1-1
7.0.1-10
7.0.1-2
7.0.1-3
7.0.1-4
7.0.1-5
7.0.1-6
7.0.1-7
7.0.1-8
7.0.1-9
7.0.2-0
7.0.2-1
7.0.2-10
7.0.2-2
7.0.2-3
7.0.2-4
7.0.2-5
7.0.2-6
7.0.2-7
7.0.2-8
7.0.2-9
7.0.3-0