CVE-2017-16546: Buffer Overflow
Published Nov 5, 2017
·Updated
Last updated 24 July 2024
Other sources
The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does ...
— Debian
Affected Software
8 affected componentsFixes available
ImageMagick ImageMagick=7.0.7-9
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=16.04
Canonical Ubuntu Linux=17.10
Canonical Ubuntu Linux=18.04
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/imagemagick
8:6.9.11.60+dfsg-1.3+deb11u48:6.9.11.60+dfsg-1.3+deb11u58:6.9.11.60+dfsg-1.6+deb12u28:6.9.11.60+dfsg-1.6+deb12u18:7.1.1.43+dfsg1-18:7.1.1.47+dfsg1-1
Remediation
Patch Available
Event History
Nov 5, 2017
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:32 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·10:47 PM
RemedyDescriptionSeverityAffected Software
Feb 26, 2025
Data Sourced
via Debian·11:33 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-16546.
2
What is the severity of CVE-2017-16546?
The severity of CVE-2017-16546 is rated as high with a score of 8.8.
3
What software is affected by CVE-2017-16546?
The affected software includes ImageMagick versions 7.0.7-9 and Ubuntu packages imagemagick, as well as Canonical Ubuntu Linux and Debian Debian Linux versions specified in the references.
4
How does CVE-2017-16546 impact systems?
CVE-2017-16546 can result in a denial of service (use of uninitialized data or invalid memory allocation) or other unspecified impacts.
5
How can I fix the CVE-2017-16546 vulnerability?
To fix the CVE-2017-16546 vulnerability, you should update ImageMagick to version 8:6.9.7.4+dfsg-16ubuntu2.2 or later, as specified in the references.