First published: Mon Aug 28 2017(Updated: )
Last updated 24 July 2024
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | <6.9.9-6 | |
ImageMagick ImageMagick | >=7.0.0-0<7.0.6-6 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
Canonical Ubuntu Linux | =14.04 | |
Canonical Ubuntu Linux | =16.04 | |
Canonical Ubuntu Linux | =17.10 | |
Canonical Ubuntu Linux | =18.04 | |
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u4 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u2 8:6.9.11.60+dfsg-1.6+deb12u1 8:7.1.1.39+dfsg1-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-12877 is medium with a severity value of 6.5.
CVE-2017-12877 affects ImageMagick versions before 7.0.6-6.
Remote attackers can exploit CVE-2017-12877 by using a crafted file to cause a denial of service.
Yes, Ubuntu provides fixes for CVE-2017-12877 with the following versions: 8:6.9.7.4+dfsg-16ubuntu2.2, 8:6.9.7.4+dfsg-16ubuntu6.2, 8:6.9.9.34+dfsg-3, 8:6.8.9.9-7ubuntu5.11, and 8:6.7.7.10-6ubuntu3.11.
You can find more information about CVE-2017-12877 at the following references: http://www.openwall.com/lists/oss-security/2017/08/16/2, https://blogs.gentoo.org/ago/2017/08/10/imagemagick-use-after-free-in-destroyimage-image-c/, and https://github.com/ImageMagick/ImageMagick/commit/04178de2247e353fc095846784b9a10fefdbf890.