First published: Sun Jul 23 2017(Updated: )
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the WriteOnePNGImage() function in coders/png.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | =7.0.6-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11538 has been classified as a medium-severity vulnerability due to its potential impact on memory management.
CVE-2017-11538 affects ImageMagick by causing a memory leak when processing specially crafted files with the convert command.
CVE-2017-11538 specifically affects ImageMagick version 7.0.6-1.
To fix CVE-2017-11538, you should upgrade to a version of ImageMagick that is newer than 7.0.6-1, where this vulnerability has been patched.
CVE-2017-11538 can potentially be exploited remotely if an attacker is able to trick a victim into processing a malicious crafted PNG file.