CVE-2017-12936: Use After Free
Published Aug 18, 2017
·Updated
Last updated 25 August 2025
Other sources
The ReadWMFImage function in coders/wmf.c in GraphicsMagick 1.3.26 has a use-after-free issue for data associated with exception reporting.
— Launchpad
Affected Software
4 affected componentsFixes available
GraphicsMagick Graphicsmagick=1.3.26
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/graphicsmagick
1.4+really1.3.36+hg16481-2+deb11u11.4+really1.3.40-4+deb12u11.4+really1.3.45+hg17696-11.4+really1.3.46-2
Remediation
Patch Available
Event History
Aug 18, 2017
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:20 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:21 PM
DescriptionAffected Software
Data Sourced
via Launchpad·08:21 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-12936.
2
What is the severity of CVE-2017-12936?
The severity of CVE-2017-12936 is high (8.8).
3
Which software is affected by CVE-2017-12936?
GraphicsMagick versions 1.3.26 are affected by CVE-2017-12936.
4
What is the remedy for CVE-2017-12936?
Upgrade to GraphicsMagick versions 1.4+really1.3.35-1~deb10u2, 1.4+really1.3.35-1~deb10u3, 1.4+really1.3.36+hg16481-2+deb11u1, 1.4+really1.3.40-4, or 1.4+really1.3.42-1 to fix CVE-2017-12936.
5
Where can I find more information about CVE-2017-12936?
You can find more information about CVE-2017-12936 at the following references: [1] [2] [3].