First published: Tue Apr 18 2017(Updated: )
The ReadSVGImage function in svg.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | =7.0.5-4 | |
Debian Linux | =8.0 | |
Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7943 is classified as a high severity vulnerability due to its potential for denial of service through memory consumption.
To fix CVE-2017-7943, upgrade ImageMagick to the latest version that addresses this vulnerability.
CVE-2017-7943 allows remote attackers to exploit ImageMagick's ReadSVGImage function to exhaust system memory.
CVE-2017-7943 specifically affects ImageMagick version 7.0.5-4.
CVE-2017-7943 is primarily a remote exploit, allowing attackers to consume memory by uploading crafted SVG files.