Heap-based buffer overflow in the DrawImage function in magick/draw.c in ImageMagick before 6.9.5-5 allows remote attackers to cause a denial of service (application crash) via a crafted image file.
{ "vanir_signatures": [ { "id": "CVE-2016-10046-90cf14aa", "digest": { "length": 34630.0, "function_hash": "105821297934886641033004172548266479551" }, "source": "https://github.com/imagemagick/imagemagick/commit/989f9f88ea6db09b99d25586e912c921c0da8d3f", "signature_version": "v1", "target": { "function": "DrawImage", "file": "magick/draw.c" }, "deprecated": false, "signature_type": "Function" }, { "id": "CVE-2016-10046-b43115ee", "digest": { "line_hashes": [ "111474618106123245942052817755198756272", "301954155546171996711090723027809067481", "279975694698735176382484669604413338546", "183001078492337674961672731704068361015" ], "threshold": 0.9 }, "source": "https://github.com/imagemagick/imagemagick/commit/989f9f88ea6db09b99d25586e912c921c0da8d3f", "signature_version": "v1", "target": { "file": "magick/draw.c" }, "deprecated": false, "signature_type": "Line" } ] }