GraphicsMagick CVE-2017-14997 Denial of Service Vulnerability
BID:101183
CVE-2017-14997 |Info
GraphicsMagick CVE-2017-14997 Denial of Service Vulnerability
| Bugtraq ID: | 101183 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2017-14997 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 03 2017 12:00AM |
| Updated: | Oct 03 2017 12:00AM |
| Credit: | Kirit Sankar Gupta. |
| Vulnerable: |
GraphicsMagick GraphicsMagick 1.3.26 |
| Not Vulnerable: | |
Discussion
GraphicsMagick CVE-2017-14997 Denial of Service Vulnerability
GraphicsMagick is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to cause denial-of-service conditions.
GraphicsMagick 1.3.26 is vulnerable; other versions may also be affected.
GraphicsMagick is prone to a remote denial-of-service vulnerability.
Attackers can exploit this issue to cause denial-of-service conditions.
GraphicsMagick 1.3.26 is vulnerable; other versions may also be affected.
Exploit / POC
GraphicsMagick CVE-2017-14997 Denial of Service Vulnerability
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
The researcher who discovered this issue has created a proof-of-concept. Please see the references for more information.
Solution / Fix
GraphicsMagick CVE-2017-14997 Denial of Service Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
GraphicsMagick CVE-2017-14997 Denial of Service Vulnerability
References:
References:
- #511 Memory Allocation error due to malformed image file (Sourceforge)
- GraphicsMagick Homepage (GraphicsMagick)
- PICT: Avoid unsigned underflow leading to astonishingly large allocation request (Graphicsmagick)
- PICT: Avoid unsigned underflow leading to astonishingly large allocation request (Sourceforge)