CVE-2017-12435: High severity imagemagick vulnerability
In ImageMagick 7.0.6-1, a memory exhaustion vulnerability was found in the function ReadSUNImage in coders/sun.c, which allows attackers to cause a denial of service.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-12435?
CVE-2017-12435 is a memory exhaustion vulnerability found in ImageMagick 7.0.6-1.
How does CVE-2017-12435 impact ImageMagick?
CVE-2017-12435 allows attackers to cause a denial of service in ImageMagick.
What is the severity of CVE-2017-12435?
The severity of CVE-2017-12435 is high with a CVSSv3 score of 7.5.
How can I fix CVE-2017-12435 on Ubuntu?
To fix CVE-2017-12435 on Ubuntu, update ImageMagick to version 8:6.7.7.10-6ubuntu3.11, 8:6.9.7.4+dfsg-16, or 8:6.8.9.9-7ubuntu5.11 depending on your Ubuntu release.
How can I fix CVE-2017-12435 on Debian?
To fix CVE-2017-12435 on Debian, update ImageMagick to version 8:6.9.10.23+dfsg-2.1+deb10u1, 8:6.9.10.23+dfsg-2.1+deb10u5, 8:6.9.11.60+dfsg-1.3+deb11u1, 8:6.9.11.60+dfsg-1.6, or 8:6.9.12.98+dfsg1-2 depending on your Debian release.