CVE-2017-8765: High severity imagemagick vulnerability
Published May 4, 2017
·Updated
The function named ReadICONImage in coders\icon.c in ImageMagick 7.0.5-5 has a memory leak vulnerability which can cause memory exhaustion via a crafted ICON file.
Affected Software
1 affected component
ImageMagick=7.0.5-5
Remediation
Patch Available
Event History
May 4, 2017
CVE Published
via MITRE·03:55 AM
Data Sourced
via MITRE·03:55 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-8765?
CVE-2017-8765 has been assigned a medium severity rating due to its potential for causing memory exhaustion.
2
How do I fix CVE-2017-8765?
To fix CVE-2017-8765, update to a patched version of ImageMagick later than 7.0.5-5.
3
What type of file triggers the vulnerability in CVE-2017-8765?
CVE-2017-8765 is triggered by processing a crafted ICON file.
4
What is the impact of CVE-2017-8765?
The impact of CVE-2017-8765 is that it can lead to memory leaks and potential system instability.
5
Which version of ImageMagick is affected by CVE-2017-8765?
CVE-2017-8765 affects ImageMagick version 7.0.5-5.