Memory leak in ImageMagick - CVE-2017-9098
Published: May 26, 2017 / Updated: May 30, 2017
Vulnerability identifier: #VU6836
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-9098
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to memory leak in in the RLE decoder in ImageMagick before 7.0.5-2 . A remote attacker can create create a specially crafted image file and gain access to certain parts of memory and trigger application crash.
Affected software
ImageMagick
imagemagick (Debian package)
Ubuntu
imagemagick (Debian package)
Ubuntu
How to mitigate CVE-2017-9098
Update to version 7.0.5-2.