Blog | G5 Cyber Security

Vulnerability Spotlight: ImageMagick Convert Tiff Out of Bounds Write

Talos is disclosing an out of bounds write vulnerability in ImageMagick. The vulnerability occurs when attempting to deflate an Adobe Deflate compressed Tiff image. The buffer that is created to hold decompressed data associated with the Tiff image is not large enough to hold the decompressed stream. Under proper circumstances, the vulnerability could be exploited into full remote code execution. The full details surrounding the vulnerability are available here. The following Snort Rules will detect exploitation attempts. For the most current rule information, please refer to your FireSIGHT Management Center or Snort.org.”]

Source: https://blog.talosintelligence.com/2016/12/ImageMagick-Tiff-out-of-Bounds.html

Exit mobile version