ImageMagick CVE-2017-14224 Heap Buffer Overflow Vulnerability
BID:100702
CVE-2017-14224 |Info
ImageMagick CVE-2017-14224 Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 100702 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2017-14224 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 08 2017 12:00AM |
| Updated: | Sep 08 2017 12:00AM |
| Credit: | lifuhao from Aliyun Security Team. |
| Vulnerable: |
ImageMagick ImageMagick 7.0.6-8 |
| Not Vulnerable: | |
Discussion
ImageMagick CVE-2017-14224 Heap Buffer Overflow Vulnerability
ImageMagick is prone to a heap-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely cause a denial-of-service condition.
ImageMagick is prone to a heap-based buffer-overflow vulnerability because it fails to adequately bounds-check user-supplied data before copying it into an insufficiently sized buffer.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will likely cause a denial-of-service condition.
Solution / Fix
ImageMagick CVE-2017-14224 Heap Buffer Overflow Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
ImageMagick CVE-2017-14224 Heap Buffer Overflow Vulnerability
References:
References:
- Heap buffer overflow in WritePCXImage #733 (ImageMagick)
- ImageMagick Homepage (ImageMagick)