PT-2017-18723 · Imagemagick+2 · Imagemagick+2
Published
2017-05-22
·
Updated
2020-10-15
·
CVE-2017-9141
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
ImageMagick version 7.0.5-7 Q16
Description
A crafted file could trigger an assertion failure in the ResetImageProfileIterator function due to missing checks in the ReadDDSImage function.
Recommendations
For ImageMagick version 7.0.5-7 Q16, consider updating to a newer version that addresses the issue in the ResetImageProfileIterator function and the ReadDDSImage function.
Fix
RCE
Assertion Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Imagemagick
Suse
Ubuntu