CVE-2017-11524: Medium severity imagemagick vulnerability
The WriteBlob function in MagickCore/blob.c in ImageMagick before 6.9.8-10 and 7.x before 7.6.0-0 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11524?
CVE-2017-11524 has been classified as a denial of service vulnerability due to assertion failures causing application exits.
How do I fix CVE-2017-11524?
To remediate CVE-2017-11524, upgrade to ImageMagick version 6.9.8-10 or later, or any 7.x version after 7.6.0-0.
What platforms are affected by CVE-2017-11524?
CVE-2017-11524 affects ImageMagick versions prior to 6.9.8-10 and several 7.x versions up to and including 7.0.5-10.
Can CVE-2017-11524 be exploited remotely?
Yes, CVE-2017-11524 can be exploited by remote attackers through crafted files.
What is the impact of CVE-2017-11524 on systems using ImageMagick?
The impact of CVE-2017-11524 is the potential for denial of service attacks, which can result in application crashes.