First published: Wed Aug 23 2017(Updated: )
In GraphicsMagick 1.3.26, an allocation failure vulnerability was found in the function ReadMNGImage in coders/png.c when a small MNG file has a MEND chunk with a large length value.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/graphicsmagick | 1.4+really1.3.36+hg16481-2+deb11u1 1.4+really1.3.40-4 1.4+really1.3.45-1 | |
ImageMagick | =1.3.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-13147 has a high severity due to its potential to cause allocation failures in GraphicsMagick.
To fix CVE-2017-13147, you should upgrade GraphicsMagick to version 1.4+really1.3.36+hg16481-2+deb11u1 or later.
CVE-2017-13147 affects GraphicsMagick version 1.3.26.
Yes, CVE-2017-13147 can cause application crashes due to allocation failures.
CVE-2017-13147 is notably relevant for users of Debian-based systems that run GraphicsMagick.