Junglewise Threat Intelligence

CVE-2016-7906: ImageMagick use-after-free in magick/attribute.c

CVE-2016-7906 · Severity: medium · CVSS 5.5 · Published 2017-01-18

Technologies: Debian Linux, ImageMagick. Vendors: Debian, ImageMagick.

Executive brief

ImageMagick, a widely used suite for image processing and manipulation, is vulnerable to a memory handling error. An attacker can provide a specially crafted image file that, when processed by the software, causes it to crash. This results in a denial of service, potentially disrupting automated workflows or web services that rely on ImageMagick for image conversion.

Technical details

A use-after-free vulnerability exists in ImageMagick 7.0.3-2 within the SetImageDepth function in magick/attribute.c. The issue is triggered when processing a crafted image file (such as a TIFF) using utilities like 'mogrify' or 'identify'. The root cause involves improper management of image colormaps where memory is accessed after being relinquished. An attacker can achieve a denial of service (application crash) by enticing a user or automated system to process a malicious file. The vulnerability was addressed by ensuring proper colormap acquisition via AcquireImageColormap.

Affected products

  • ImageMagick ImageMagick 7.0.3-2

Timeline

  • 2016-09-30: disclosed: Issue reported on GitHub by Marco Grassi
  • 2016-10-02: patched: Fix committed to ImageMagick repository
  • 2017-01-18: advisory: NVD publication date

References

Related threats