CVE-2017-18028: High severity imagemagick vulnerability
Published Jan 12, 2018
·Updated
In ImageMagick 7.0.7-1 Q16, a memory exhaustion vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allow remote attackers to cause a denial of service via a crafted file.
Affected Software
6 affected componentsFixes available
ImageMagick=7.0.7-1-q16
Ubuntu Linux=14.04
Ubuntu Linux=16.04
Ubuntu Linux=17.10
Ubuntu Linux=18.04
debian/imagemagick
8:6.9.11.60+dfsg-1.3+deb11u48:6.9.11.60+dfsg-1.3+deb11u58:6.9.11.60+dfsg-1.6+deb12u28:6.9.11.60+dfsg-1.6+deb12u18:7.1.1.43+dfsg1-18:7.1.1.47+dfsg1-1
Remediation
Event History
Jan 12, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:35 PM
Description
Sep 15, 2024
Data Sourced
via Ubuntu·10:48 PM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2017-18028?
CVE-2017-18028 is a memory exhaustion vulnerability discovered in the ReadTIFFImage function in ImageMagick 7.0.7-1 Q16.
2
How does CVE-2017-18028 affect ImageMagick?
CVE-2017-18028 allows remote attackers to cause a denial of service in ImageMagick.
3
What is the severity of CVE-2017-18028?
The severity of CVE-2017-18028 is high, with a severity value of 6.5.
4
How can I fix CVE-2017-18028 in ImageMagick on Ubuntu?
To fix CVE-2017-18028 in ImageMagick on Ubuntu, update to version 8:6.9.7.4+dfsg-16ubuntu2.2 or later.
5
Where can I find more information about CVE-2017-18028?
You can find more information about CVE-2017-18028 on the GitHub page for ImageMagick and the Ubuntu Security Notice.