MagickCore/profile.c in ImageMagick before 7.0.3-2 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted file.
{ "vanir_signatures": [ { "id": "CVE-2016-7799-43eed044", "digest": { "line_hashes": [ "55538535849838087017497805556919473556", "261128923802723148554592281260328158853", "16546488639457447087166482182796893989", "113630145063465390056385546323268763450" ], "threshold": 0.9 }, "target": { "file": "MagickCore/profile.c" }, "signature_version": "v1", "source": "https://github.com/imagemagick/imagemagick/commit/a7bb158b7bedd1449a34432feb3a67c8f1873bfa", "deprecated": false, "signature_type": "Line" }, { "id": "CVE-2016-7799-aee00c44", "digest": { "length": 3572.0, "function_hash": "160235545997546523496287174794181439555" }, "target": { "function": "SyncExifProfile", "file": "MagickCore/profile.c" }, "signature_version": "v1", "source": "https://github.com/imagemagick/imagemagick/commit/a7bb158b7bedd1449a34432feb3a67c8f1873bfa", "deprecated": false, "signature_type": "Function" } ] }