CVE-2017-16547: Input Validation
Last updated 25 August 2025
Other sources
The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of service (negative strncpy and application crash) or possibly have unspecified other impact via a crafted file.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this GraphicsMagick vulnerability?
The vulnerability ID for this GraphicsMagick vulnerability is CVE-2017-16547.
What is the severity of CVE-2017-16547?
The severity of CVE-2017-16547 is high with a severity value of 8.8.
How does CVE-2017-16547 impact GraphicsMagick?
CVE-2017-16547 can cause a denial of service (negative strncpy and application crash) or possibly have unspecified other impact.
Which versions of GraphicsMagick are affected by CVE-2017-16547?
GraphicsMagick versions 1.3.26 and earlier are affected by CVE-2017-16547.
How can I fix CVE-2017-16547 in GraphicsMagick?
To fix CVE-2017-16547 in GraphicsMagick, it is recommended to update to version 1.3.26-18 or later.