Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.1.2.2016.683
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DLA-683-1)
Summary:The remote host is missing an update for the Debian 'graphicsmagick' package(s) announced via the DLA-683-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'graphicsmagick' package(s) announced via the DLA-683-1 advisory.

Vulnerability Insight:
Several vulnerabilities have been found in the graphicsmagick package that may lead to denial of service through failed assertions, CPU or memory usage. Some vulnerabilities may also lead to code execution but no exploit is currently known.

CVE-2016-7448

Utah RLE: Reject truncated/absurd files which caused huge memory allocations and/or consumed huge CPU

CVE-2016-7996

missing check that the provided colormap is not larger than 256 entries resulting in potential heap overflow

CVE-2016-7997

denial of service via a crash due to an assertion

CVE-2016-8682

stack-based buffer overflow in ReadSCTImage (sct.c)

CVE-2016-8683

memory allocation failure in ReadPCXImage (pcx.c)

CVE-2016-8684

memory allocation failure in MagickMalloc (memory.c)

For Debian 7 Wheezy, these problems have been fixed in version 1.3.16-1.1+deb7u5.

We recommend that you upgrade your graphicsmagick packages.

Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: [link moved to references]

Affected Software/OS:
'graphicsmagick' package(s) on Debian 7.

Solution:
Please install the updated package(s).

CVSS Score:
7.8

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2016-7448
BugTraq ID: 93074
http://www.securityfocus.com/bid/93074
https://lists.debian.org/debian-lts-announce/2018/06/msg00009.html
http://www.openwall.com/lists/oss-security/2016/09/18/8
SuSE Security Announcement: openSUSE-SU-2016:2641 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-10/msg00094.html
SuSE Security Announcement: openSUSE-SU-2016:2644 (Google Search)
http://lists.opensuse.org/opensuse-updates/2016-10/msg00097.html
Common Vulnerability Exposure (CVE) ID: CVE-2016-7996
BugTraq ID: 93464
http://www.securityfocus.com/bid/93464
Debian Security Information: DSA-3746 (Google Search)
http://www.debian.org/security/2016/dsa-3746
http://www.openwall.com/lists/oss-security/2016/10/07/4
http://www.openwall.com/lists/oss-security/2016/10/08/5
Common Vulnerability Exposure (CVE) ID: CVE-2016-7997
BugTraq ID: 93467
http://www.securityfocus.com/bid/93467
Common Vulnerability Exposure (CVE) ID: CVE-2016-8682
BugTraq ID: 93597
http://www.securityfocus.com/bid/93597
https://blogs.gentoo.org/ago/2016/09/15/graphicsmagick-stack-based-buffer-overflow-in-readsctimage-sct-c/
http://www.openwall.com/lists/oss-security/2016/10/16/6
Common Vulnerability Exposure (CVE) ID: CVE-2016-8683
BugTraq ID: 93600
http://www.securityfocus.com/bid/93600
https://blogs.gentoo.org/ago/2016/09/15/graphicsmagick-memory-allocation-failure-in-readpcximage-pcx-c/
http://www.openwall.com/lists/oss-security/2016/10/16/7
Common Vulnerability Exposure (CVE) ID: CVE-2016-8684
BugTraq ID: 93779
http://www.securityfocus.com/bid/93779
https://blogs.gentoo.org/ago/2016/09/15/graphicsmagick-memory-allocation-failure-in-magickmalloc-memory-c/
http://www.openwall.com/lists/oss-security/2016/10/16/15
CopyrightCopyright (C) 2023 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.