#VU38717 Input validation error in ImageMagick - CVE-2017-11166
Published: July 10, 2017 / Updated: August 8, 2020
ImageMagick
ImageMagick.org
Description
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The ReadXWDImage function in codersxwd.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via a crafted length (number of color-map entries) field in the header of an XWD file.