CVE-2017-7943: Medium severity ImageMagick ImageMagick vulnerability
Published Apr 18, 2017
·Updated
The ReadSVGImage function in svg.c in ImageMagick 7.0.5-4 allows remote attackers to consume an amount of available memory via a crafted file.
Affected Software
3 affected components
ImageMagick ImageMagick=7.0.5-4
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
Apr 18, 2017
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:59 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2017-7943?
CVE-2017-7943 is classified as a high severity vulnerability due to its potential for denial of service through memory consumption.
2
How do I fix CVE-2017-7943?
To fix CVE-2017-7943, upgrade ImageMagick to the latest version that addresses this vulnerability.
3
What affect does CVE-2017-7943 have on ImageMagick?
CVE-2017-7943 allows remote attackers to exploit ImageMagick's ReadSVGImage function to exhaust system memory.
4
Which versions of ImageMagick are affected by CVE-2017-7943?
CVE-2017-7943 specifically affects ImageMagick version 7.0.5-4.
5
Can CVE-2017-7943 be exploited by local users?
CVE-2017-7943 is primarily a remote exploit, allowing attackers to consume memory by uploading crafted SVG files.