CVE-2017-17913: High severity GraphicsMagick Graphicsmagick vulnerability
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility with libwebp versions, 0.5.0 and later, that use a different structure type.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-17913?
CVE-2017-17913 is a vulnerability in GraphicsMagick 1.4 snapshot-20171217 Q8 that allows for a stack-based buffer over-read in WriteWEBPImage in coders/webp.c.
How severe is CVE-2017-17913?
CVE-2017-17913 has a severity rating of 8.8 out of 10.
Which software versions are affected by CVE-2017-17913?
CVE-2017-17913 affects GraphicsMagick versions 1.3.27-3, 1.3.23-1ubuntu0.6, and 1.3.27. It also affects Debian Linux 9.0 and some versions of graphicsmagick in Debian and Ubuntu systems.
How can I fix CVE-2017-17913?
To fix CVE-2017-17913, update GraphicsMagick to version 1.3.27-3 or install the appropriate security update for your Debian or Ubuntu system.
Where can I find more information about CVE-2017-17913?
More information about CVE-2017-17913 can be found at the following references: [CVE-2017-17913](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-17913), [GraphicsMagick commit 88313ebe379c](http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/88313ebe379c), [GraphicsMagick commit 6dda3c33f35f](http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/6dda3c33f35f).