CVE-2017-12140 PUBLISHED

The ReadDCMImage function in coders\dcm.c in ImageMagick 7.0.6-1 has an integer signedness error leading to excessive memory consumption via a crafted DCM file.

EPSS 0.96% · 76.3th percentile

Risk Scores

EPSS Score
0.96%
76.3th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSimagemagick8:6.7.7.10-6ubuntu3.4, 8:6.7.7.10-6ubuntu3.9, 8:6.7.7.10-6ubuntu3.8
Ubuntu:16.04:LTSimagemagick8:6.8.9.9-7ubuntu5.9, 8:6.8.9.9-7ubuntu5.3, 8:6.8.9.9-7ubuntu5.4
Ubuntu:18.04:LTSimagemagick8:6.9.7.4+dfsg-16ubuntu6, 8:6.9.7.4+dfsg-16ubuntu5, 8:6.9.7.4+dfsg-16ubuntu4

Timeline

References

Open in Interactive Console →