Resource exhaustion in GraphicsMagick - CVE-2017-11140
Published: July 10, 2017 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a local non-authenticated attacker to perform a denial of service (DoS) attack.
The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a pixel cache before a successful read of a scanline, which allows remote attackers to cause a denial of service (resource consumption) via crafted JPEG files.
Affected software
Amazon Linux AMI
Fedora
graphicsmagick (Alpine package)
GraphicsMagick
How to mitigate CVE-2017-11140
GraphicsMagick - addressed in versions 1.3.28-1.el6, 1.3.28-1.el7, 1.3.28-1.fc26, 1.3.28-1.fc27