CVE-2017-12877: Use After Free
Last updated 24 July 2024
Other sources
Use-after-free vulnerability in the DestroyImage function in image.c i ...
— Debian
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2017-12877?
The severity of CVE-2017-12877 is medium with a severity value of 6.5.
How does CVE-2017-12877 affect ImageMagick?
CVE-2017-12877 affects ImageMagick versions before 7.0.6-6.
How can remote attackers exploit CVE-2017-12877?
Remote attackers can exploit CVE-2017-12877 by using a crafted file to cause a denial of service.
Is there a fix available for CVE-2017-12877 in Ubuntu?
Yes, Ubuntu provides fixes for CVE-2017-12877 with the following versions: 8:6.9.7.4+dfsg-16ubuntu2.2, 8:6.9.7.4+dfsg-16ubuntu6.2, 8:6.9.9.34+dfsg-3, 8:6.8.9.9-7ubuntu5.11, and 8:6.7.7.10-6ubuntu3.11.
Where can I find more information about CVE-2017-12877?
You can find more information about CVE-2017-12877 at the following references: http://www.openwall.com/lists/oss-security/2017/08/16/2, https://blogs.gentoo.org/ago/2017/08/10/imagemagick-use-after-free-in-destroyimage-image-c/, and https://github.com/ImageMagick/ImageMagick/commit/04178de2247e353fc095846784b9a10fefdbf890.