PT-2017-2812 · Imagemagick+2 · Imagemagick+2

Shqking

+2

·

Publicado

2017-08-31

·

Atualizado

2020-10-15

·

CVE-2017-14172

CVSS v2.0

7.1

Alta

VetorAV:N/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ImageMagick version 7.0.7-0 Q16
Description The issue is related to a lack of an EOF (End of File) check in the ReadPSImage() function, which can cause huge CPU consumption. This occurs when a crafted PSD file with a large "extent" field in the header but insufficient backing data is provided, leading to a loop that consumes significant CPU resources. The vulnerability can be exploited by a remote attacker to cause a denial of service by consuming computational resources.
Recommendations For ImageMagick version 7.0.7-0 Q16, consider disabling the ReadPSImage() function as a temporary workaround until a patch is available to prevent the exploitation of this issue. Restrict access to PSD files to minimize the risk of exploitation. Avoid using the length variable in the affected loop until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02084
CVE-2017-14172
DLA-1131-1
DLA-1785-1
DLA-2366-1
OPENSUSE-SU-2017_3420-1
SUSE-SU-2017:3378-1
SUSE-SU-2017:3388-1
USN-3681-1

Produtos afetados

Imagemagick
Suse
Ubuntu