Memory leak in GraphicsMagick - CVE-2017-13066
Published: May 15, 2018
Vulnerability identifier: #VU12713
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13066
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to cause DoS condition on the target system.
The weakness exists in the function CloneImage in magick/image.c due to memory leak. A remote attacker can trigger memory corruption and cause the service to crash.
Affected software
GraphicsMagick
Arch Linux
Fedora
graphicsmagick (Alpine package)
GraphicsMagick
Arch Linux
Fedora
graphicsmagick (Alpine package)
GraphicsMagick
How to mitigate CVE-2017-13066
Install update from vendor's website.
GraphicsMagick - addressed in versions 1.3.34-1.el7, 1.3.34-1.el8