CVE-2017-16546 PUBLISHED

The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or possibly have unspecified other impact via a malformed WPG file.

EPSS 0.59% · 69.1th percentile

Risk Scores

EPSS Score
0.59%
69.1th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSimagemagick0, 8:6.9.7.4+dfsg-16ubuntu6, 8:6.9.7.4+dfsg-16ubuntu5
Ubuntu:16.04:LTSimagemagick8:6.8.9.9-7ubuntu1, 8:6.8.9.9-6build1, 8:6.8.9.9-7
Ubuntu:14.04:LTSimagemagick8:6.7.7.10-6ubuntu3.2, 8:6.7.7.10-6ubuntu3.3, 8:6.7.7.10-6ubuntu3.4

Timeline

References

Open in Interactive Console →