CVE-2017-5510: High severity ImageMagick ImageMagick vulnerability
coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted PSD file, which triggers an out-of-bounds write.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.7.4+dfsg-1Fixed in 8:6.8.9.9-5+deb8u7 - Upgrade
Upgrade
debian/imagemagickto a version that resolves this vulnerability.Fixed in 8:6.9.11.60+dfsg-1.3+deb11u4Fixed in 8:6.9.11.60+dfsg-1.3+deb11u3Fixed in 8:6.9.11.60+dfsg-1.6+deb12u2Fixed in 8:6.9.11.60+dfsg-1.6+deb12u1Fixed in 8:6.9.13.12+dfsg1-1Fixed in 8:7.1.1.39+dfsg1-2
Event History
Frequently Asked Questions
What is the severity of CVE-2017-5510?
CVE-2017-5510 is classified as critical due to its potential for remote code execution through an out-of-bounds write.
How do I fix CVE-2017-5510?
To fix CVE-2017-5510, upgrade ImageMagick to a version that is not vulnerable, starting from 8:6.9.7.4+dfsg-1 or later.
Which versions of ImageMagick are affected by CVE-2017-5510?
CVE-2017-5510 affects ImageMagick versions up to and including 8:6.9.7.4 and earlier.
Can I use older versions of ImageMagick after CVE-2017-5510?
Using older versions of ImageMagick that are affected by CVE-2017-5510 is highly discouraged due to security risks.
What types of attacks can CVE-2017-5510 facilitate?
CVE-2017-5510 can allow remote attackers to execute arbitrary code via crafted PSD files.