First published: Wed Jul 26 2017(Updated: )
GraphicsMagick 1.3.26 has a heap overflow in the WriteRGBImage() function in coders/rgb.c when processing multiple frames that have non-identical widths.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/graphicsmagick | 1.4+really1.3.36+hg16481-2+deb11u1 1.4+really1.3.40-4 1.4+really1.3.45-1 | |
ImageMagick | =1.3.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11636 is classified as a high severity vulnerability due to the potential for a heap overflow that could allow an attacker to execute arbitrary code.
You can fix CVE-2017-11636 by upgrading to versions 1.4+really1.3.36+hg16481-2+deb11u1, 1.4+really1.3.40-4, or 1.4+really1.3.45-1 of GraphicsMagick.
CVE-2017-11636 specifically affects GraphicsMagick version 1.3.26.
CVE-2017-11636 involves a heap overflow in the WriteRGBImage() function when processing multiple frames with non-identical widths.
While there is no public proof-of-concept exploit reported for CVE-2017-11636, the nature of the vulnerability poses a significant risk.