First published: Sun Jul 23 2017(Updated: )
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the GetPixelIndex() function, called from the WritePICONImage function in coders/xpm.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | =7.0.6-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11540 has been rated as a medium severity vulnerability due to its potential to cause heap-based buffer over-reads.
To mitigate CVE-2017-11540, upgrade ImageMagick to at least version 7.0.6-2 or later.
CVE-2017-11540 can lead to an application crash or can potentially expose sensitive memory contents when processing specially crafted image files.
CVE-2017-11540 affects ImageMagick version 7.0.6-1.
No, CVE-2017-11540 is not related to directory traversal attacks; it specifically concerns heap-based buffer over-reads.