PublicDateAtUSN: 2016-12-31 Candidate: CVE-2016-10144 PublicDate: 2017-03-24 15:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10144 http://www.openwall.com/lists/oss-security/2017/01/16/6 https://ubuntu.com/security/notices/USN-3222-1 Description: coders/ipl.c in ImageMagick allows remote attackers to have unspecific impact by leveraging a missing malloc check. Ubuntu-Description: Notes: mdeslaur> This is 0172-Ipl-file-missing-malloc-check.patch Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851485 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H [9.8 CRITICAL] Patches_imagemagick: upstream: https://github.com/ImageMagick/ImageMagick/commit/97566cf2806c0a5a86e884c96831a0c3b1ec6c20 upstream_imagemagick: released (8:6.9.7.4+dfsg-1) precise_imagemagick: released (8:6.6.9.7-5ubuntu3.8) trusty_imagemagick: released (8:6.7.7.10-6ubuntu3.5) trusty/esm_imagemagick: DNE (trusty was released [8:6.7.7.10-6ubuntu3.5]) vivid/stable-phone-overlay_imagemagick: DNE vivid/ubuntu-core_imagemagick: DNE xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.5) esm-infra/xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.5) yakkety_imagemagick: released (8:6.8.9.9-7ubuntu8.4) devel_imagemagick: released (8:6.9.7.4+dfsg-2ubuntu3)