CVE-2017-17783: High severity GraphicsMagick Graphicsmagick vulnerability
Published Dec 20, 2017
·Updated
In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8.
Affected Software
3 affected componentsFixes available
GraphicsMagick Graphicsmagick=1.3.27a
Debian Debian Linux=9.0
debian/graphicsmagick
1.4+really1.3.36+hg16481-2+deb11u11.4+really1.3.40-4+deb12u11.4+really1.3.45+hg17696-11.4+really1.3.46-2
Remediation
Event History
Dec 20, 2017
CVE Published
via MITRE·09:00 AM
Data Sourced
via MITRE·09:00 AM
Description
Data Sourced
via NVD·09:29 AM
DescriptionSeverityWeaknessAffected Software
Feb 19, 2026
Data Sourced
via Ubuntu·09:44 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·09:44 PM
Description
Data Sourced
via Debian·09:45 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-17783?
The severity of CVE-2017-17783 is high.
2
What is the affected software of CVE-2017-17783?
The affected software of CVE-2017-17783 is GraphicsMagick 1.3.27a.
3
How can I fix CVE-2017-17783?
To fix CVE-2017-17783, update GraphicsMagick to version 1.3.23-1ubuntu0.5 if using Ubuntu, or follow the recommended updates for Debian.
4
Where can I find more information about CVE-2017-17783?
You can find more information about CVE-2017-17783 at the following references: [Reference 1](http://hg.graphicsmagick.org/hg/GraphicsMagick?cmd=changeset;node=60932931559a), [Reference 2](https://sourceforge.net/p/graphicsmagick/bugs/529/), [Reference 3](https://www.debian.org/security/2018/dsa-4321).
5
What is the Common Weakness Enumeration (CWE) of CVE-2017-17783?
The Common Weakness Enumeration (CWE) of CVE-2017-17783 is CWE-125.