First published: Wed Aug 30 2017(Updated: )
A memory allocation failure was discovered in the ReadPNMImage function in coders/pnm.c in GraphicsMagick 1.3.26. The vulnerability causes a big memory allocation, which may lead to remote denial of service in the MagickRealloc function in magick/memory.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/graphicsmagick | 1.4+really1.3.36+hg16481-2+deb11u1 1.4+really1.3.40-4 1.4+really1.3.45-1 | |
ImageMagick | =1.3.26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14042 is classified as a denial-of-service vulnerability that can significantly impact system availability.
To fix CVE-2017-14042, upgrade to GraphicsMagick version 1.4+really1.3.36+hg16481-2+deb11u1 or later.
CVE-2017-14042 affects GraphicsMagick version 1.3.26, which contains a vulnerability in the ReadPNMImage function.
Yes, CVE-2017-14042 can be exploited remotely, leading to a denial-of-service due to excessive memory allocation.
Yes, CVE-2017-14042 is patched in versions later than 1.3.26 of GraphicsMagick.