First published: Sun Dec 24 2017(Updated: )
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to a WEBP_DECODER_ABI_VERSION check.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | =7.0.7-16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17880 has a high severity due to the potential for a stack-based buffer over-read.
To resolve CVE-2017-17880, upgrade ImageMagick to a version later than 7.0.7-16.
The impact of CVE-2017-17880 can allow an attacker to exploit the buffer over-read, potentially leading to denial of service or exposure of sensitive information.
CVE-2017-17880 affects ImageMagick version 7.0.7-16 and earlier versions.
CVE-2017-17880 specifically involves the WriteWEBPImage function located in the coders/webp.c file of ImageMagick.