First published: Mon Jul 10 2017(Updated: )
ImageMagick is vulnerable to a denial of service, caused by a memory-leak issue in the ReadXWDImage function in coders\xwd.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to consume all available memory from the system.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ImageMagick 7.0.5 | <6 | 6 |
redhat/ImageMagick 6.9.8 | <1 | 1 |
IBM Data Risk Manager | <=2.0.6 | |
ImageMagick | =7.0.5-6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11166 is classified as a denial of service vulnerability due to a memory leak.
To fix CVE-2017-11166, update to the latest version of ImageMagick or apply the recommended patches provided by the vendor.
CVE-2017-11166 affects ImageMagick versions up to 7.0.5-6 and specific versions of IBM Data Risk Manager up to 2.0.6.
Yes, CVE-2017-11166 can be exploited remotely if a victim opens a specially-crafted image file.
The impact of CVE-2017-11166 includes exhaustion of system memory, leading to denial of service.