PT-2017-2263 · Imagemagick+3 · Imagemagick+3
Published
2017-01-17
·
Updated
2020-10-15
·
CVE-2017-5507
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 6.9.7-4
ImageMagick versions 7.x prior to 7.0.4-4
Description
The issue is related to a memory leak in the coders/mpc.c component of the ImageMagick console graphic editor. This can be exploited by a remote attacker to cause a denial of service through memory consumption, using vectors that involve the pixel cache.
Recommendations
For ImageMagick versions prior to 6.9.7-4, update to version 6.9.7-4 or later.
For ImageMagick versions 7.x prior to 7.0.4-4, update to version 7.0.4-4 or later.
Fix
DoS
Missing Release of Resource after Effective Lifetime
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Imagemagick
Suse
Ubuntu