Executive brief
ImageMagick, a widely used software suite for displaying and converting image files, is vulnerable to a denial-of-service attack. By providing a specially crafted SGI image file with an abnormally large row value, a remote attacker can cause the application to crash. This could lead to service interruptions for websites or applications that automatically process user-uploaded images.
Technical details
An out-of-bounds read vulnerability exists in the SGI coder component of ImageMagick. The root cause is insufficient validation of the 'row' value within the SGI image header. When processing a crafted SGI file with a large row value, the 'IdentifyImageGray' and 'IsPixelMonochrome' functions may attempt to read memory outside of the allocated buffer, leading to a segmentation fault. This attack is delivered via a malicious file and requires a user or automated process to attempt to identify or convert the image. The issue was addressed in versions 7.0.2-10 and 6.9.5-8 by improving header validation and EOF checks.
Affected products
- ImageMagick ImageMagick before 7.0.2-10, before 6.9.5-8
Timeline
- 2016-08-15: patched: Fix committed to ImageMagick repository
- 2016-09-26: disclosed: Public disclosure on oss-security mailing list
- 2017-01-18: advisory: NVD publication date
References
- http://www.openwall.com/lists/oss-security/2016/09/26/8
- http://www.securityfocus.com/bid/93181
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=836776
- https://github.com/ImageMagick/ImageMagick/commit/7afcf9f71043df15508e46f079387bd4689a738d
- https://github.com/ImageMagick/ImageMagick/commit/8f8959033e4e59418d6506b345829af1f7a71127