CVE-2017-5508 PUBLISHED

Heap-based buffer overflow in the PushQuantumPixel function in ImageMagick before 6.9.7-3 and 7.x before 7.0.4-3 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF file.

EPSS 0.54% · 67.6th percentile

Risk Scores

EPSS Score
0.54%
67.6th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSimagemagick8:6.8.9.9-7ubuntu5.4, 8:6.8.9.9-6build1, 8:6.8.9.9-7
Ubuntu:14.04:LTSimagemagick8:6.7.7.10-5ubuntu3, 8:6.7.7.10-5ubuntu4, 8:6.7.7.10-6ubuntu1

Timeline

References

Open in Interactive Console →