CVE-2017-15032: Critical severity ImageMagick vulnerability
Published Oct 5, 2017
·Updated
ImageMagick version 7.0.7-2 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
Affected Software
10 affected componentsFixes available
ImageMagick=7.0.7-2
Ubuntu Linux=14.04
Ubuntu Linux=16.04
Ubuntu Linux=17.10
Ubuntu Linux=18.04
debian/imagemagick
8:6.9.11.60+dfsg-1.3+deb11u48:6.9.11.60+dfsg-1.3+deb11u38:6.9.11.60+dfsg-1.6+deb12u28:6.9.11.60+dfsg-1.6+deb12u18:7.1.1.43+dfsg1-18:7.1.1.47+dfsg1-1
Ubuntu=14.04
Ubuntu=16.04
Ubuntu=17.10
Ubuntu=18.04
Remediation
Event History
Oct 5, 2017
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:31 PM
Description
Sep 19, 2024
Data Sourced
via Ubuntu·10:48 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2017-15032?
CVE-2017-15032 is a vulnerability in ImageMagick version 7.0.7-2 that contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
2
How severe is CVE-2017-15032?
CVE-2017-15032 is considered critical with a severity value of 9.8.
3
How can I fix CVE-2017-15032 on Ubuntu?
To fix CVE-2017-15032 on Ubuntu, update the imagemagick package to version 8:6.9.7.4+dfsg-16ubuntu2.2 or later.
4
How can I fix CVE-2017-15032 on Debian?
To fix CVE-2017-15032 on Debian, update the imagemagick package to version 8:6.9.10.23+dfsg-2.1+deb10u1 or later.
5
Where can I find more information about CVE-2017-15032?
For more information about CVE-2017-15032, you can refer to the GitHub commit, Ubuntu security advisory, and the Launchpad bug report mentioned in the references.