Buffer overflow in ImageMagick - CVE-2017-15281
Published: October 12, 2017 / Updated: September 8, 2020
ImageMagick
Detailed vulnerability description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
ReadPSDImage in coders/psd.c in ImageMagick 7.0.7-6 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, related to "Conditional jump or move depends on uninitialised value(s)."
How to mitigate CVE-2017-15281
Sources
- http://www.securityfocus.com/bid/101276
- https://github.com/ImageMagick/ImageMagick/issues/832
- https://lists.debian.org/debian-lts-announce/2019/05/msg00015.html
- https://lists.debian.org/debian-lts-announce/2020/09/msg00007.html
- https://security.gentoo.org/glsa/201711-07
- https://usn.ubuntu.com/3681-1/