CVE-2016-2318

GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath function in magick/render.c.
Configurations

Configuration 1 (hide)

cpe:2.3:a:graphicsmagick:graphicsmagick:1.3.23:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:a:suse:linux_enterprise_debuginfo:11:sp4:*:*:*:*:*:*
cpe:2.3:a:suse:studio_onsite:1.3:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:leap:42.1:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.2:*:*:*:*:*:*:*
cpe:2.3:o:suse:linux_enterprise_software_development_kit:11:sp4:*:*:*:*:*:*

History

No history.

Information

Published : 2017-02-03 15:59

Updated : 2023-12-10 12:01


NVD link : CVE-2016-2318

Mitre link : CVE-2016-2318

CVE.ORG link : CVE-2016-2318


JSON object : View

Products Affected

opensuse

  • leap
  • opensuse

suse

  • linux_enterprise_debuginfo
  • linux_enterprise_software_development_kit
  • studio_onsite

debian

  • debian_linux

graphicsmagick

  • graphicsmagick
CWE
CWE-476

NULL Pointer Dereference