CVE-2017-11139: Double Free
Published Jul 10, 2017
·Updated
GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.
Affected Software
3 affected componentsFixes available
debian/graphicsmagick
1.4+really1.3.35-1~deb10u21.4+really1.3.35-1~deb10u31.4+really1.3.36+hg16481-2+deb11u11.4+really1.3.40-41.4+really1.3.42-1
GraphicsMagick Graphicsmagick=1.3.26
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Jul 10, 2017
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11139?
CVE-2017-11139 has been classified as a medium severity vulnerability due to the potential for a crash or denial of service.
2
How do I fix CVE-2017-11139?
To remediate CVE-2017-11139, upgrade to GraphicsMagick version 1.4+really1.3.35-1~deb10u2 or later.
3
Which versions of GraphicsMagick are affected by CVE-2017-11139?
CVE-2017-11139 affects GraphicsMagick version 1.3.26.
4
Is CVE-2017-11139 specific to certain operating systems?
CVE-2017-11139 is particularly noted for its impact on Debian Linux.
5
What is the nature of the vulnerability in CVE-2017-11139?
CVE-2017-11139 involves double free vulnerabilities within the ReadOneJNGImage() function of GraphicsMagick.