CVE-2017-16545: Null Pointer Dereference
Last updated 25 August 2025
Other sources
The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows remote attackers to cause a denial of service (ImportIndexQuantumType invalid write and application crash) or possibly have unspecified other impact via a malformed WPG image.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2017-16545.
What is the title of the vulnerability?
The title of the vulnerability is 'The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colorm…'
How does the vulnerability affect GraphicsMagick?
The vulnerability allows remote attackers to cause a denial of service or possibly have unspecified other impact through a malformed WPG image.
What is the severity of CVE-2017-16545?
The severity of CVE-2017-16545 is high with a CVSS score of 8.8.
How can I fix the vulnerability?
To fix the vulnerability, update GraphicsMagick to version 1.3.18-1ubuntu3.1+ or higher.