CVE-2017-13776: High severity GraphicsMagick Graphicsmagick vulnerability
GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version!=10 case that results in the reader not returning; it would cause large amounts of CPU and memory consumption although the crafted file itself does not request it.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-13776?
CVE-2017-13776 is a denial-of-service vulnerability in GraphicsMagick 1.3.26 that results in high CPU and memory consumption.
How does CVE-2017-13776 affect GraphicsMagick?
CVE-2017-13776 affects GraphicsMagick versions 1.3.23-1ubuntu0.3 and earlier, as well as 1.3.18-1ubuntu3.1+ and earlier.
What is the severity of CVE-2017-13776?
CVE-2017-13776 has a severity rating of 6.5 (High).
How can I fix CVE-2017-13776?
To fix CVE-2017-13776, update GraphicsMagick to version 1.3.23-1ubuntu0.3 or later for Ubuntu, or version 1.3.18-1ubuntu3.1+ or later for Trusty. Alternatively, update to a later version of GraphicsMagick that includes the necessary security patches.
Where can I find more information about CVE-2017-13776?
You can find more information about CVE-2017-13776 on the following websites: [1] http://openwall.com/lists/oss-security/2017/08/31/2 [2] http://hg.code.sf.net/p/graphicsmagick/code/rev/233a720bfd5e [3] http://www.securityfocus.com/bid/100574