CVE-2017-12428: High severity imagemagick vulnerability
Published Aug 4, 2017
·Updated
In ImageMagick 7.0.6-1, a memory leak vulnerability was found in the function ReadWMFImage in coders/wmf.c, which allows attackers to cause a denial of service in CloneDrawInfo in draw.c.
Affected Software
2 affected componentsFixes available
debian/imagemagick
8:6.9.10.23+dfsg-2.1+deb10u18:6.9.10.23+dfsg-2.1+deb10u58:6.9.11.60+dfsg-1.3+deb11u18:6.9.11.60+dfsg-1.68:6.9.12.98+dfsg1-48:6.9.12.98+dfsg1-5
ImageMagick=7.0.6-1
Remediation
Patch Available
Event History
Aug 4, 2017
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-12428?
CVE-2017-12428 is classified as a medium severity vulnerability due to potential denial of service risks.
2
How do I fix CVE-2017-12428?
To mitigate CVE-2017-12428, upgrade ImageMagick to versions 6.9.10.23+dfsg-2.1+deb10u1 or later.
3
What type of vulnerability is CVE-2017-12428?
CVE-2017-12428 is a memory leak vulnerability found in the ReadWMFImage function.
4
Which versions of ImageMagick are affected by CVE-2017-12428?
ImageMagick version 7.0.6-1 and below are affected by CVE-2017-12428.
5
What impact does CVE-2017-12428 have on applications?
CVE-2017-12428 can lead to denial of service by causing memory leaks during image processing.