CVE-2017-11636: Buffer Overflow
GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in coders/rgb.c when processing multiple frames that have non-identical widths.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-11636?
CVE-2017-11636 is classified as a high severity vulnerability due to the potential for a heap overflow that could allow an attacker to execute arbitrary code.
How do I fix CVE-2017-11636?
You can fix CVE-2017-11636 by upgrading to versions 1.4+really1.3.36+hg16481-2+deb11u1, 1.4+really1.3.40-4, or 1.4+really1.3.45-1 of GraphicsMagick.
What software is affected by CVE-2017-11636?
CVE-2017-11636 specifically affects GraphicsMagick version 1.3.26.
What is the nature of the vulnerability in CVE-2017-11636?
CVE-2017-11636 involves a heap overflow in the WriteRGBImage() function when processing multiple frames with non-identical widths.
Is there a known exploit for CVE-2017-11636?
While there is no public proof-of-concept exploit reported for CVE-2017-11636, the nature of the vulnerability poses a significant risk.