CVE-2017-13737: Use After Free
Published Aug 29, 2017
·Updated
Last updated 25 August 2025
Other sources
There is an invalid free in the MagickFree function in magick/memory.c in GraphicsMagick 1.3.26 that will lead to a remote denial of service attack.
— Launchpad
Affected Software
4 affected componentsFixes available
GraphicsMagick Graphicsmagick=1.3.26
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/graphicsmagick
1.4+really1.3.36+hg16481-2+deb11u11.4+really1.3.40-4+deb12u11.4+really1.3.45+hg17696-11.4+really1.3.46-2
Remediation
Event History
Aug 29, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:20 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·08:21 PM
Description
Data Sourced
via Debian·08:21 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-13737.
2
What is the severity of CVE-2017-13737?
The severity of CVE-2017-13737 is medium.
3
Which versions of GraphicsMagick are affected by CVE-2017-13737?
GraphicsMagick version 1.3.26 is affected by CVE-2017-13737.
4
How do I fix CVE-2017-13737 in Ubuntu?
To fix CVE-2017-13737 in Ubuntu, update GraphicsMagick package to versions 1.3.18-1ubuntu3.1 or later.
5
Is Debian Linux affected by CVE-2017-13737?
Yes, Debian Linux versions 8.0 and 9.0 are affected by CVE-2017-13737.