MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/ImageMagick/ImageMagick/commits/7.0.2-1 | third party advisory patch |
http://www.securityfocus.com/bid/91394 | exploit vdb entry third party advisory |
http://www.oracle.com/technetwork/topics/security/bulletinjul2016-3090568.html | third party advisory |
https://security.gentoo.org/glsa/201611-21 | third party advisory vendor advisory |
http://www.openwall.com/lists/oss-security/2016/06/25/3 | mailing list exploit third party advisory |
https://github.com/ImageMagick/ImageMagick/commit/d8ab7f046587f2e9f734b687ba7e6e10147c294b | third party advisory patch |
http://www.openwall.com/lists/oss-security/2016/06/23/1 | mailing list third party advisory patch |