CVE-2017-11140: High severity GraphicsMagick Graphicsmagick vulnerability
Last updated 25 August 2025
Other sources
The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a pixel cache before a successful read of a scanline, which allows remote attackers to cause a denial of service (resource consumption) via crafted JPEG files.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11140?
CVE-2017-11140 is classified as a denial of service vulnerability that can lead to resource exhaustion.
How do I fix CVE-2017-11140?
To fix CVE-2017-11140, upgrade to GraphicsMagick versions 1.4+really1.3.36+hg16481-2+deb11u1, 1.4+really1.3.40-4, or 1.4+really1.3.45-1.
What is the impact of CVE-2017-11140?
The impact of CVE-2017-11140 is that it allows remote attackers to consume system resources, potentially leading to service downtime.
Which versions of GraphicsMagick are affected by CVE-2017-11140?
CVE-2017-11140 affects GraphicsMagick version 1.3.26.
Who can exploit CVE-2017-11140?
CVE-2017-11140 can be exploited by remote attackers using crafted JPEG files.