First published: Mon Sep 11 2017(Updated: )
A heap-based buffer over-read in SampleImage() in MagickCore/resize.c in ImageMagick 7.0.6-8 Q16 allows remote attackers to cause a denial of service via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | =7.0.6-8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14248 is classified as a moderate severity vulnerability, allowing remote attackers to cause a denial of service.
To fix CVE-2017-14248, upgrade ImageMagick to version 7.0.6-9 or later.
CVE-2017-14248 can lead to a denial of service through heap-based buffer over-read when processing crafted image files.
Yes, CVE-2017-14248 can be exploited remotely by providing a specially crafted file.
CVE-2017-14248 affects ImageMagick version 7.0.6-8.