CVE-2017-14175: High severity imagemagick vulnerability
In coders/xbm.c in ImageMagick 7.0.6-1 Q16, a DoS in ReadXBMImage() du ...
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-14175?
CVE-2017-14175 is a vulnerability in ImageMagick 7.0.6-1 Q16 that can cause a Denial of Service (DoS) due to lack of an EOF (End of File) check, leading to high CPU consumption.
How does CVE-2017-14175 affect ImageMagick?
CVE-2017-14175 affects ImageMagick versions 7.0.6-1 Q16 and earlier.
What is the severity of CVE-2017-14175?
CVE-2017-14175 has a severity rating of 6.5 (High).
How can I fix CVE-2017-14175?
To fix CVE-2017-14175, upgrade ImageMagick to version 8:6.7.7.10-6ubuntu3.11, 8:6.9.9.34+dfsg-3, 8:6.8.9.9-7ubuntu5.11, 8:6.9.7.4+dfsg-16ubuntu2.2, 8:6.9.7.4+dfsg-16ubuntu6.2, 7.0.6-1, 8:6.9.10.23+dfsg-2.1+deb10u1, 8:6.9.10.23+dfsg-2.1+deb10u5, 8:6.9.11.60+dfsg-1.3+deb11u1, 8:6.9.11.60+dfsg-1.6, 8:6.9.12.98+dfsg1-2, depending on your system.
Where can I find more information about CVE-2017-14175?
You can find more information about CVE-2017-14175 at the following references: [link1](https://github.com/ImageMagick/ImageMagick/issues/712), [link2](https://security.gentoo.org/glsa/201711-07), [link3](https://usn.ubuntu.com/3681-1/).