CVE-2017-17502: High severity GraphicsMagick Graphicsmagick vulnerability
Last updated 25 August 2025
Other sources
ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this GraphicsMagick vulnerability?
The vulnerability ID for this GraphicsMagick vulnerability is CVE-2017-17502.
What is the severity of CVE-2017-17502?
The severity of CVE-2017-17502 is high with a CVSS score of 8.8.
What is the affected software for CVE-2017-17502?
The affected software for CVE-2017-17502 is GraphicsMagick version 1.3.26.
How can I fix the vulnerability CVE-2017-17502?
To fix the vulnerability CVE-2017-17502, update GraphicsMagick to a version that includes the fix, such as 1.3.27-1 or higher.
Where can I find more information about CVE-2017-17502?
You can find more information about CVE-2017-17502 on the following references: [Reference 1](http://hg.code.sf.net/p/graphicsmagick/code/rev/a9c425688397), [Reference 2](https://sourceforge.net/p/graphicsmagick/bugs/521/), [Reference 3](https://lists.debian.org/debian-lts-announce/2018/01/msg00005.html).