First published: Mon Mar 06 2017(Updated: )
An issue was discovered in ImageMagick 6.9.7. A specially crafted webp file could lead to a file-descriptor leak in libmagickcore (thus, a DoS).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | =6.9.7 | |
debian/imagemagick | 8:6.9.10.23+dfsg-2.1+deb10u1 8:6.9.10.23+dfsg-2.1+deb10u5 8:6.9.11.60+dfsg-1.3+deb11u1 8:6.9.11.60+dfsg-1.6 8:6.9.12.98+dfsg1-4 8:6.9.12.98+dfsg1-5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-6502 is classified as a denial of service (DoS) vulnerability due to a file-descriptor leak in ImageMagick.
To fix CVE-2017-6502, upgrade ImageMagick to versions 6.9.10.23 or later as specified in the official patches.
CVE-2017-6502 affects ImageMagick version 6.9.7.
CVE-2017-6502 can be exploited using specially crafted webp files.
Yes, CVE-2017-6502 can potentially lead to a denial of service, resulting in system instability.