CVE-2017-9142 PUBLISHED

In ImageMagick 7.0.5-7 Q16, a crafted file could trigger an assertion failure in the WriteBlob function in MagickCore/blob.c because of missing checks in the ReadOneJNGImage function in coders/png.c.

EPSS 1.40% · 80.3th percentile

Risk Scores

EPSS Score
1.40%
80.3th percentile

Affected Products

VendorProductVersions
Ubuntu:16.04:LTSimagemagick8:6.8.9.9-7ubuntu5.6, 8:6.8.9.9-6build1, 8:6.8.9.9-7
Ubuntu:14.04:LTSimagemagick8:6.7.7.10-5ubuntu3, 8:6.7.7.10-5ubuntu4, 8:6.7.7.10-6ubuntu1

Timeline

References

Open in Interactive Console →