CVE-2017-12431: Use After Free
In ImageMagick 7.0.6-1, a use-after-free vulnerability was found in th ...
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-12431?
CVE-2017-12431 is a use-after-free vulnerability in ImageMagick 7.0.6-1 that allows attackers to cause a denial of service.
Which software versions are affected by CVE-2017-12431?
The affected software versions include ImageMagick 7.0.6-1, 6.7.7.10-6ubuntu3.11, 6.9.7.4+dfsg-13, and 6.8.9.9-7ubuntu5.11.
What is the severity of CVE-2017-12431?
The severity of CVE-2017-12431 is medium with a CVSS score of 6.5.
How can I fix CVE-2017-12431?
To fix CVE-2017-12431, you should update to ImageMagick versions 8:6.7.7.10-6ubuntu3.11, 8:6.9.7.4+dfsg-13, or 8:6.8.9.9-7ubuntu5.11, depending on the affected software version.
Where can I find more information about CVE-2017-12431?
You can find more information about CVE-2017-12431 at the following references: [Reference 1](https://github.com/ImageMagick/ImageMagick/issues/555), [Reference 2](https://www.debian.org/security/2017/dsa-4019), [Reference 3](https://www.debian.org/security/2017/dsa-4040).