CVE-2017-16547 PUBLISHED

The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of service (negative strncpy and application crash) or possibly have unspecified other impact via a crafted file.

EPSS 0.86% · 74.9th percentile

Risk Scores

EPSS Score
0.86%
74.9th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSgraphicsmagick0, 1.3.16-1.1ubuntu2, 1.3.16-1.1ubuntu3
Ubuntu:16.04:LTSgraphicsmagick0, 1.3.21-3, 1.3.23-1

Timeline

References

Open in Interactive Console →