CVE-2017-9141: Input Validation
Published May 22, 2017
·Updated
In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the ResetImageProfileIterator function in MagickCore/profile.c because of missing checks in the ReadDDSImage function in coders/dds.c.
Affected Software
3 affected components
ImageMagick ImageMagick=7.0.5-7
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Remediation
Patch Available
Event History
May 22, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-9141?
CVE-2017-9141 has been classified as a moderate severity vulnerability affecting ImageMagick.
2
How do I fix CVE-2017-9141?
To fix CVE-2017-9141, upgrade to a version of ImageMagick newer than 7.0.5-7 that includes the necessary patches.
3
What impact does CVE-2017-9141 have on my system?
CVE-2017-9141 can lead to an assertion failure, potentially causing service disruption when processing crafted image files.
4
Which versions of ImageMagick are affected by CVE-2017-9141?
CVE-2017-9141 specifically affects ImageMagick version 7.0.5-7.
5
Is my Debian system at risk from CVE-2017-9141?
Debian systems running ImageMagick version 7.0.5-7 are at risk from CVE-2017-9141 and should be updated to secure versions.