Candidate: CVE-2016-8866 PublicDate: 2017-02-15 19:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-8866 https://blogs.gentoo.org/ago/2016/10/20/imagemagick-memory-allocation-failure-in-acquiremagickmemory-memory-c-incomplete-fix-for-cve-2016-8862/ https://www.imagemagick.org/discourse-server/viewtopic.php?f=3&t=30908#p140255 Description: The AcquireMagickMemory function in MagickCore/memory.c in ImageMagick 7.0.3.3 before 7.0.3.8 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-8862. Ubuntu-Description: Notes: mdeslaur> incomplete fix of CVE-2016-8862 mdeslaur> Upstream says it's an issue with address sanitizer throwing the mdeslaur> error before malloc() and mmap() return failure. Marking as mdeslaur> ignored. Bugs: Priority: medium Discovered-by: Agostino Sarubbo Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [8.8 HIGH] nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H [7.8 HIGH] Patches_imagemagick: upstream_imagemagick: needs-triage precise_imagemagick: ignored trusty_imagemagick: ignored trusty/esm_imagemagick: DNE (trusty was ignored) vivid/stable-phone-overlay_imagemagick: DNE vivid/ubuntu-core_imagemagick: DNE xenial_imagemagick: ignored esm-infra/xenial_imagemagick: ignored yakkety_imagemagick: ignored devel_imagemagick: ignored