CVE-2017-5509: High severity ImageMagick vulnerability
Published Jan 14, 2017
·Updated
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an out-of-bounds write.
Affected Software
5 affected components
debian/8:6.9.6.6+dfsg-2<=undefined
debian/imagemagick<=8:6.8.9.9-5, <=8:6.8.9.9-5+deb8u6, <=8:6.7.7.10-5, <=8:6.9.6.6+dfsg-1
ImageMagick<6.9.7-4
ImageMagick>=7.0.0-0<7.0.4-4
ImageMagick
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Mar 24, 2017
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Data Sourced
via NVD·03:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-5509?
CVE-2017-5509 has a critical severity due to the potential for remote attackers to exploit the vulnerability via crafted PSD files.
2
How do I fix CVE-2017-5509?
To fix CVE-2017-5509, update to a patched version of ImageMagick that resolves the out-of-bounds write vulnerability.
3
What versions of ImageMagick are affected by CVE-2017-5509?
CVE-2017-5509 affects ImageMagick versions up to 6.9.7-4 and versions between 7.0.0-0 and 7.0.4-4.
4
What impact does CVE-2017-5509 have on systems?
CVE-2017-5509 can lead to unexpected application crashes or potentially allow remote code execution on affected systems.
5
Is my system vulnerable to CVE-2017-5509?
If you are using an affected version of ImageMagick noted in the CVE-2017-5509 description, your system is potentially vulnerable.