CVE-2017-13777: High severity GraphicsMagick Graphicsmagick vulnerability
Published Aug 30, 2017
·Updated
GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version==10 case that results in the reader not returning; it would cause large amounts of CPU and memory consumption although the crafted file itself does not request it.
Affected Software
4 affected componentsFixes available
GraphicsMagick Graphicsmagick=1.3.26
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/graphicsmagick
1.4+really1.3.36+hg16481-2+deb11u11.4+really1.3.40-4+deb12u11.4+really1.3.45+hg17696-11.4+really1.3.46-2
Remediation
Patch Available
Event History
Aug 30, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:29 PM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:20 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:21 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-13777.
2
What is the severity level of CVE-2017-13777?
The severity level of CVE-2017-13777 is high.
3
Which software versions are affected by CVE-2017-13777?
GraphicsMagick 1.3.26 is affected by CVE-2017-13777.
4
How can I fix CVE-2017-13777?
Upgrade to GraphicsMagick version 1.3.23-1ubuntu0.3 or higher.
5
Where can I find more information about CVE-2017-13777?
You can find more information about CVE-2017-13777 at the following references: http://openwall.com/lists/oss-security/2017/08/31/1, http://hg.code.sf.net/p/graphicsmagick/code/rev/233a720bfd5e, http://www.securityfocus.com/bid/100575