CVE-2016-7906

Source
Severity High
Remote Yes
Type Arbitrary code execution
Description
An attacker is able to trigger a use-after-free when providing a crafted image to ImageMagick's mogrify function.
Group Package Affected Fixed Severity Status Ticket
AVG-40 imagemagick 6.9.5.10-1 6.9.6.0-1 High Fixed
Date Advisory Group Package Severity Description
08 Oct 2016 ASA-201610-6 AVG-40 imagemagick High multiple issues
References
https://github.com/ImageMagick/ImageMagick/issues/281
https://github.com/ImageMagick/ImageMagick/commit/d63a3c5729df59f183e9e110d5d8385d17caaad0
http://www.openwall.com/lists/oss-security/2016/10/02/3
Notes
Fix has been backported to 9.6.9-0