Rapid7

vulnerability

Ubuntu: USN-3131-1 (CVE-2016-5842): ImageMagick vulnerabilities

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Nov 21, 2016
Added
Nov 21, 2016
Modified
Mar 27, 2026

Description

MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.

Solutions

ubuntu-upgrade-imagemagickubuntu-upgrade-imagemagick-6-q16ubuntu-upgrade-libmagick-4ubuntu-upgrade-libmagick-5ubuntu-upgrade-libmagick-6-q16-5v5ubuntu-upgrade-libmagickcore-6-q16-2ubuntu-upgrade-libmagickcore-6-q16-2-extraubuntu-upgrade-libmagickcore4ubuntu-upgrade-libmagickcore4-extraubuntu-upgrade-libmagickcore5ubuntu-upgrade-libmagickcore5-extra
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.