CVE-2016-8866 PUBLISHED

The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick 7.0.3.3 before 7.0.3.8 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8862.

EPSS 0.48% · 64.7th percentile

Risk Scores

EPSS Score
0.48%
64.7th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSimagemagick0, 8:6.7.7.10-5ubuntu3, 8:6.7.7.10-5ubuntu4
Ubuntu:Pro:16.04:LTSimagemagick0, 8:6.8.9.9-5ubuntu2, 8:6.8.9.9-6

Timeline

References

Open in Interactive Console →