CVE-2017-11403: Use After Free
Last updated 25 August 2025
Other sources
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11403?
CVE-2017-11403 is classified as a medium severity vulnerability due to its potential for exploitation through crafted files.
How do I fix CVE-2017-11403?
To fix CVE-2017-11403, upgrade GraphicsMagick to one of the patched versions such as 1.4+really1.3.36+hg16481-2+deb11u1 or later.
What is the impact of CVE-2017-11403?
CVE-2017-11403 can lead to a use-after-free condition, which may allow an attacker to execute arbitrary code.
Which versions of GraphicsMagick are affected by CVE-2017-11403?
GraphicsMagick version 1.3.26 is known to be affected by CVE-2017-11403.
Is CVE-2017-11403 specific to any operating system?
CVE-2017-11403 has been reported in GraphicsMagick on Debian-based systems, but may affect other platforms using the vulnerable version.