CVE-2017-17501: High severity GraphicsMagick Graphicsmagick vulnerability
Published Dec 11, 2017
·Updated
Last updated 25 August 2025
Other sources
WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file.
— Debian
Affected Software
5 affected componentsFixes available
GraphicsMagick Graphicsmagick=1.3.26
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/graphicsmagick
1.4+really1.3.36+hg16481-2+deb11u11.4+really1.3.40-4+deb12u11.4+really1.3.45+hg17696-11.4+really1.3.46-2
Remediation
Patch Available
Event History
Dec 11, 2017
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·02:29 AM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 19, 2026
Data Sourced
via Ubuntu·09:44 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·09:44 PM
Description
Data Sourced
via Debian·09:45 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-17501.
2
What is the severity of CVE-2017-17501?
The severity of CVE-2017-17501 is high with a CVSS score of 8.8.
3
Which software is affected by CVE-2017-17501?
GraphicsMagick versions 1.3.18-1ubuntu3.1+ to 1.3.26 are affected.
4
How can I fix CVE-2017-17501?
Upgrade to a version of GraphicsMagick that is not affected, such as versions 1.3.27-1 or later.
5
Where can I find more information about CVE-2017-17501?
You can find more information about CVE-2017-17501 at the following references: [1] http://hg.code.sf.net/p/graphicsmagick/code/rev/5b8414c0d0c4 [2] https://sourceforge.net/p/graphicsmagick/bugs/526/ [3] http://www.securityfocus.com/bid/102185