First published: Fri May 18 2018(Updated: )
In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-25, there is a use-after-free in ReadOneMNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted MNG image file that is mishandled in an MngInfoDiscardObject call.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | >=7.0.7-16<7.0.7-21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-18272 has a high severity rating due to its potential to cause denial of service.
To mitigate CVE-2017-18272, upgrade ImageMagick to version 7.0.7-22 or later.
CVE-2017-18272 affects ImageMagick versions from 7.0.7-16 to 7.0.7-21.
CVE-2017-18272 is a use-after-free vulnerability found in the handling of crafted MNG image files.
Yes, CVE-2017-18272 can be exploited remotely through the processing of malicious MNG image files.