First published: Fri Jun 02 2017(Updated: )
In ImageMagick 7.0.5-5, the ReadMPCImage function in mpc.c allows attackers to cause a denial of service (memory leak) via a crafted file.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | =7.0.5-5 | |
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u4 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u2 8:6.9.11.60+dfsg-1.6+deb12u1 8:7.1.1.39+dfsg1-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9409 is a vulnerability in ImageMagick 7.0.5-5 that allows attackers to cause a denial of service (memory leak) via a crafted file.
The affected versions include ImageMagick 7.0.5-5, 6.9.7.4+dfsg-11, 6.8.9.9-7ubuntu5.8, 6.9.7.4+dfsg-3ubuntu1.2, 6.7.7.10-6ubuntu3.8, 7.0.5-5, 6.9.10.23+dfsg-2.1+deb10u1, 6.9.10.23+dfsg-2.1+deb10u5, 6.9.11.60+dfsg-1.3+deb11u1, 6.9.11.60+dfsg-1.6, and 6.9.12.98+dfsg1-2.
The severity of CVE-2017-9409 is medium with a severity score of 6.5.
To fix CVE-2017-9409, you should update ImageMagick to version 8:6.9.7.4+dfsg-11 or apply the recommended patches for your specific distribution.
You can find more information about CVE-2017-9409 on GitHub, Launchpad, and Debian Security Tracker.