CVE-2016-5842 PUBLISHED

MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.

EPSS 1.39% · 80.3th percentile

Risk Scores

EPSS Score
1.39%
80.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSimagemagick8:6.8.9.9-7ubuntu5.1, 8:6.8.9.9-6build1, 8:6.8.9.9-7
Ubuntu:14.04:LTSimagemagick8:6.7.7.10-5ubuntu3, 8:6.7.7.10-5ubuntu4, 8:6.7.7.10-6ubuntu1

Timeline

References

Open in Interactive Console →