CVE-2017-11352: Medium severity ImageMagick ImageMagick vulnerability
Published Jul 17, 2017
·Updated
In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144.
Affected Software
8 affected componentsFixes available
ImageMagick ImageMagick<6.9.8-9
ImageMagick ImageMagick>=7.0.0-0<7.0.5-10
Debian Debian Linux=8.0
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
debian/imagemagick
8:6.9.11.60+dfsg-1.3+deb11u48:6.9.11.60+dfsg-1.3+deb11u58:6.9.11.60+dfsg-1.6+deb12u28:6.9.11.60+dfsg-1.6+deb12u18:7.1.1.43+dfsg1-18:7.1.1.47+dfsg1-1
Remediation
Patch Available
Patch Available
Event History
Jul 17, 2017
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:24 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:18 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-11352.
2
What is the severity level of CVE-2017-11352?
The severity level of CVE-2017-11352 is medium.
3
Which version of ImageMagick is affected by CVE-2017-11352?
Versions up to and excluding 7.0.5-10 of ImageMagick are affected by CVE-2017-11352.
4
How can I fix CVE-2017-11352?
To fix CVE-2017-11352, you should update ImageMagick to version 7.0.5-10 or later.
5
Where can I find more information about CVE-2017-11352?
You can find more information about CVE-2017-11352 in the references section of this page.