CVE-2017-11530: High severity imagemagick vulnerability
The ReadEPTImage function in coders/ept.c in ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1 allows remote attackers to cause a denial of service (memory consumption) via a crafted file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11530?
CVE-2017-11530 has been classified as a denial of service vulnerability due to memory consumption issues.
How do I fix CVE-2017-11530?
To address CVE-2017-11530, update ImageMagick to version 6.9.9-0 or later for the 6.x branch, or version 7.0.6-1 or later for the 7.x branch.
What types of attacks are possible with CVE-2017-11530?
Attackers can exploit CVE-2017-11530 by sending a specially crafted image file that leads to excessive memory consumption.
Which versions of ImageMagick are affected by CVE-2017-11530?
CVE-2017-11530 affects ImageMagick versions prior to 6.9.9-0 and 7.x prior to 7.0.6-1.
Is there a workaround for CVE-2017-11530?
Currently, the recommended approach is to upgrade to a patched version of ImageMagick, as there are no known workarounds for this vulnerability.