PT-2017-2561 · Imagemagick+2 · Imagemagick+2
Jgj212
·
Published
2017-07-18
·
Updated
2018-03-22
·
CVE-2017-11530
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions 6.9.9-0 and earlier
ImageMagick versions 7.x through 7.0.6-0
Description
The issue is related to the ReadEPTImage function, which allows remote attackers to cause a denial of service due to memory consumption via a crafted file. This can lead to an uncontrolled resource expenditure, enabling a remote attacker to initiate a denial of service by exploiting the vulnerability with a specially formed file.
Recommendations
For ImageMagick versions 6.9.9-0 and earlier, update to version 6.9.9-1 or later.
For ImageMagick versions 7.x through 7.0.6-0, update to version 7.0.6-1 or later.
Fix
DoS
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Imagemagick
Suse