First published: Sat Jan 14 2017(Updated: )
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an out-of-bounds write.
Credit: security@debian.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/8:6.9.6.6+dfsg-2 | <=undefined | |
debian/imagemagick | <=8:6.8.9.9-5<=8:6.8.9.9-5+deb8u6<=8:6.7.7.10-5<=8:6.9.6.6+dfsg-1 | |
ImageMagick | <6.9.7-4 | |
ImageMagick | >=7.0.0-0<7.0.4-4 | |
ImageMagick |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5509 has a critical severity due to the potential for remote attackers to exploit the vulnerability via crafted PSD files.
To fix CVE-2017-5509, update to a patched version of ImageMagick that resolves the out-of-bounds write vulnerability.
CVE-2017-5509 affects ImageMagick versions up to 6.9.7-4 and versions between 7.0.0-0 and 7.0.4-4.
CVE-2017-5509 can lead to unexpected application crashes or potentially allow remote code execution on affected systems.
If you are using an affected version of ImageMagick noted in the CVE-2017-5509 description, your system is potentially vulnerable.