CVE-2017-12937: High severity GraphicsMagick Graphicsmagick vulnerability
Last updated 25 August 2025
Other sources
The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-12937.
What is the severity of CVE-2017-12937?
The severity of CVE-2017-12937 is high with a score of 8.8.
Which software is affected by CVE-2017-12937?
The affected software is GraphicsMagick versions 1.3.26, 1.4+really1.3.35-1~deb10u2, 1.4+really1.3.35-1~deb10u3, 1.4+really1.3.36+hg16481-2+deb11u1, 1.4+really1.3.40-4, and 1.4+really1.3.42-1 on Debian. It is also affected on Ubuntu versions 1.3.23-1ubuntu0.3 (xenial) and 1.3.18-1ubuntu3.1+ (trusty).
How do I fix CVE-2017-12937?
To fix CVE-2017-12937, you should update to the patched versions: 1.4+really1.3.35-1~deb10u2, 1.4+really1.3.35-1~deb10u3, 1.4+really1.3.36+hg16481-2+deb11u1, 1.4+really1.3.40-4, or 1.4+really1.3.42-1 if you are using GraphicsMagick on Debian. On Ubuntu, update to version 1.3.23-1ubuntu0.3 (if using xenial) or version 1.3.18-1ubuntu3.1+ (if using trusty).
Are there any additional references for CVE-2017-12937?
Yes, you can find more information about CVE-2017-12937 at the following references: - [Code Commit](http://hg.code.sf.net/p/graphicsmagick/code/rev/95d00d55e978) - [SecurityFocus](http://www.securityfocus.com/bid/100442) - [Gentoo Blog](https://blogs.gentoo.org/ago/2017/08/05/graphicsmagick-heap-based-buffer-overflow-in-readsunimage-sun-c/)