CVE-2017-11478: High severity imagemagick vulnerability
Last updated 24 July 2024
Other sources
The ReadOneDJVUImage function in coders/djvu.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a malformed DJVU image.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11478?
CVE-2017-11478 has been classified as a denial of service vulnerability due to potential infinite loops and high CPU consumption.
How do I fix CVE-2017-11478?
To fix CVE-2017-11478, upgrade your ImageMagick installation to version 6.9.7.4 or later, or 7.0.6-2 or later.
Which versions of ImageMagick are affected by CVE-2017-11478?
CVE-2017-11478 affects ImageMagick versions 6.9.9-0 and 7.0.6-1 and earlier.
Can CVE-2017-11478 be exploited remotely?
Yes, CVE-2017-11478 can be exploited remotely by attackers using a malformed DJVU image.
What impact does CVE-2017-11478 have on my system?
Exploitation of CVE-2017-11478 may lead to significant denial of service by causing the server to enter an infinite loop and consume excessive CPU resources.