CVE-2017-11360: Medium severity ImageMagick vulnerability
Last updated 24 July 2024
Other sources
The ReadRLEImage function in coders\rle.c in ImageMagick 7.0.6-1 has a large loop vulnerability via a crafted rle file that triggers a huge numberpixels value.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-11360?
CVE-2017-11360 is a vulnerability found in the ReadRLEImage function in ImageMagick 7.0.6-1, which can be exploited via a crafted rle file to trigger a large loop and cause a huge number_pixels value.
What is the severity of CVE-2017-11360?
CVE-2017-11360 has a severity rating of medium with a CVSS score of 6.5.
How can CVE-2017-11360 be exploited?
CVE-2017-11360 can be exploited by using a specially crafted rle file.
Which versions of ImageMagick are affected by CVE-2017-11360?
ImageMagick versions 7.0.6-1 are affected by CVE-2017-11360.
How can I fix CVE-2017-11360?
To fix CVE-2017-11360, update to ImageMagick version 8:6.9.10.23+dfsg-2.1+deb10u1 or later, 8:6.9.11.60+dfsg-1.3+deb11u1 or later, or apply the necessary patches provided by the vendor.