CVE-2017-11641: Critical severity imagemagick vulnerability
Published Jul 26, 2017
·Updated
GraphicsMagick 1.3.26 has a Memory Leak in the PersistCache function in magick/pixelcache.c during writing of Magick Persistent Cache (MPC) files.
Affected Software
2 affected componentsFixes available
GraphicsMagick Graphicsmagick=1.3.26
debian/graphicsmagick
1.4+really1.3.36+hg16481-2+deb11u11.4+really1.3.40-41.4+really1.3.40-4+deb12u11.4+really1.3.45+hg17696-1
Event History
Jul 26, 2017
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:26 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:21 AM
RemedyDescriptionSeverityAffected Software
Mar 27, 2025
Data Sourced
via Debian·03:41 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-11641.
2
What is the severity of CVE-2017-11641?
The severity of CVE-2017-11641 is critical with a severity value of 9.8.
3
What is affected by CVE-2017-11641?
GraphicsMagick version 1.3.26 is affected by CVE-2017-11641.
4
How can I fix CVE-2017-11641?
Upgrade to GraphicsMagick version 1.4+really1.3.35-1~deb10u2 or higher, or 1.3.18-1ubuntu3.1+ or higher.
5
Where can I find more information about CVE-2017-11641?
You can find more information about CVE-2017-11641 in the references: http://hg.code.sf.net/p/graphicsmagick/code/rev/db732abd9318, https://security-tracker.debian.org/tracker/CVE-2017-11641, and https://lists.debian.org/debian-lts-announce/2018/08/msg00002.html.