CVE-2017-18229: Medium severity GraphicsMagick Graphicsmagick vulnerability
Published Mar 14, 2018
·Updated
An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via a crafted file, because file size is not properly used to restrict scanline, strip, and tile allocations.
Affected Software
5 affected componentsFixes available
GraphicsMagick Graphicsmagick=1.3.26
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/graphicsmagick
1.4+really1.3.36+hg16481-2+deb11u11.4+really1.3.40-4+deb12u11.4+really1.3.45+hg17696-11.4+really1.3.46-2
Event History
Mar 14, 2018
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·02:29 AM
DescriptionSeverityWeaknessAffected Software
Jan 11, 2024
Data Sourced
via Launchpad·10:35 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·10:11 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:12 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2017-18229.
2
What is the severity of CVE-2017-18229?
The severity of CVE-2017-18229 is medium with a CVSS score of 6.5.
3
What software is affected by CVE-2017-18229?
GraphicsMagick 1.3.26 is affected by CVE-2017-18229.
4
How can an attacker exploit CVE-2017-18229?
An attacker can exploit CVE-2017-18229 by using a crafted file to cause a denial of service.
5
How can I fix CVE-2017-18229?
To fix CVE-2017-18229, upgrade to GraphicsMagick version 1.4+really1.3.42-1 or apply the necessary patches.