CVE-2017-14989 PUBLISHED

A use-after-free in RenderFreetype in MagickCore/annotate.c in ImageMagick 7.0.7-4 Q16 allows attackers to crash the application via a crafted font file, because the FT_Done_Glyph function (from FreeType 2) is called at an incorrect place in the ImageMagick code.

EPSS 0.35% · 57.1th percentile

Risk Scores

EPSS Score
0.35%
57.1th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSimagemagick8:6.8.9.9-7ubuntu2, *, *
Ubuntu:18.04:LTSimagemagick*, 0, 8:6.9.7.4+dfsg-16ubuntu2
Ubuntu:14.04:LTSimagemagick8:6.7.7.10-6ubuntu3.9, 8:6.7.7.10-6ubuntu3.7, 8:6.7.7.10-6ubuntu3.5

Timeline

References

Open in Interactive Console →