CVE-2017-11310: High severity ImageMagick vulnerability
Published Jul 13, 2017
·Updated
The readuserchunkcallback function in coders\png.c in ImageMagick 7.0.6-1 Q16 2017-06-21 (beta) has memory leak vulnerabilities via crafted PNG files.
Affected Software
1 affected component
ImageMagick=7.0.6-1
Remediation
Patch Available
Event History
Jul 13, 2017
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-11310?
CVE-2017-11310 is rated as medium severity due to its potential for memory leaks in ImageMagick.
2
How do I fix CVE-2017-11310?
To fix CVE-2017-11310, update ImageMagick to a version later than 7.0.6-1.
3
What software versions are affected by CVE-2017-11310?
CVE-2017-11310 affects ImageMagick version 7.0.6-1.
4
What types of files can exploit CVE-2017-11310?
CVE-2017-11310 can be triggered by crafted PNG files.
5
Is CVE-2017-11310 a critical vulnerability?
No, CVE-2017-11310 is not considered critical but should still be addressed promptly.