CVE-2017-7619: High severity ImageMagick vulnerability
Published Apr 10, 2017
·Updated
In ImageMagick 7.0.4-9, an infinite loop can occur because of a floating-point rounding error in some of the color algorithms. This affects ModulateHSL, ModulateHCL, ModulateHCLp, ModulateHSB, ModulateHSI, ModulateHSV, ModulateHWB, ModulateLCHab, and ModulateLCHuv.
Affected Software
1 affected component
ImageMagick=7.0.4-9
Remediation
Event History
Apr 10, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7619?
CVE-2017-7619 is considered to have a moderate severity due to its potential impact on system stability.
2
How do I fix CVE-2017-7619?
To fix CVE-2017-7619, update ImageMagick to a version later than 7.0.4-9.
3
What types of algorithms are affected by CVE-2017-7619?
CVE-2017-7619 affects various color algorithms including ModulateHSL, ModulateHSV, and other modulation functions.
4
Can CVE-2017-7619 cause denial of service?
Yes, CVE-2017-7619 can cause denial of service by leading to an infinite loop in the affected color algorithms.
5
Which versions of ImageMagick are vulnerable to CVE-2017-7619?
ImageMagick version 7.0.4-9 is vulnerable to CVE-2017-7619.