CVE-2017-17500: High severity GraphicsMagick Graphicsmagick vulnerability
Last updated 25 August 2025
Other sources
ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a crafted file.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-17500?
CVE-2017-17500 is a vulnerability in GraphicsMagick 1.3.26 that allows for a heap-based buffer over-read via a crafted file.
How severe is CVE-2017-17500?
CVE-2017-17500 has a severity rating of 8.8 (high).
Which software versions are affected by CVE-2017-17500?
GraphicsMagick 1.3.26 is affected by CVE-2017-17500.
How can I fix CVE-2017-17500?
To fix CVE-2017-17500, you should update GraphicsMagick to a version that is not affected by this vulnerability.
Where can I find more information about CVE-2017-17500?
You can find more information about CVE-2017-17500 at the following references: [http://hg.code.sf.net/p/graphicsmagick/code/rev/1366f2dd9931](http://hg.code.sf.net/p/graphicsmagick/code/rev/1366f2dd9931), [https://sourceforge.net/p/graphicsmagick/bugs/523/](https://sourceforge.net/p/graphicsmagick/bugs/523/), [http://www.securityfocus.com/bid/102164](http://www.securityfocus.com/bid/102164).