CVE-2017-11523
published 2017-07-22CVE-2017-11523: The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite…
PriorityP425medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
3.00%
85.9th percentile
The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop) via a crafted file, because the end-of-file condition is not considered.
Affected
59 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.9.7.4+dfsg-14 (bookworm) | imagemagick 8:6.9.7.4+dfsg-14 (bookworm) |
| imagemagick | imagemagick | <= 6.9.9-0 | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | — | — |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv6.5MEDIUM
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-wffr-63m7-q9q4: The ReadTXTImage function in coders/txt
ghsa_unreviewed·2022-05-13
CVE-2017-11523 [HIGH] CWE-835 GHSA-wffr-63m7-q9q4: The ReadTXTImage function in coders/txt
The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop) via a crafted file, because the end-of-file condition is not considered.
OSV
CVE-2017-11523: The ReadTXTImage function in coders/txt
osv·2017-07-22·CVSS 6.5
CVE-2017-11523 [MEDIUM] CVE-2017-11523: The ReadTXTImage function in coders/txt
The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop) via a crafted file, because the end-of-file condition is not considered.
Red Hat
ImageMagick: Endless loop in ReadTXTImage function in coders/txt.c
vendor_redhat·2017-07-21·CVSS 6.5
CVE-2017-11523 [MEDIUM] CWE-20 ImageMagick: Endless loop in ReadTXTImage function in coders/txt.c
ImageMagick: Endless loop in ReadTXTImage function in coders/txt.c
The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop) via a crafted file, because the end-of-file condition is not considered.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 6) - Will not fix
Package: ImageMagick (Red Hat Enterprise Linux 7) - Will not fix
Package: ImageMagick (Red Hat OpenShift Enterprise 2) - Will not fix
Debian
CVE-2017-11523: imagemagick - The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x...
vendor_debian·2017·CVSS 6.5
CVE-2017-11523 [MEDIUM] CVE-2017-11523: imagemagick - The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x...
The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop) via a crafted file, because the end-of-file condition is not considered.
Scope: local
bookworm: resolved (fixed in 8:6.9.7.4+dfsg-14)
bullseye: resolved (fixed in 8:6.9.7.4+dfsg-14)
forky: resolved (fixed in 8:6.9.7.4+dfsg-14)
sid: resolved (fixed in 8:6.9.7.4+dfsg-14)
trixie: resolved (fixed in 8:6.9.7.4+dfsg-14)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2017-11523 ImageMagick: Endless loop in ReadTXTImage function in coders/txt.c
bugzilla·2017-07-25·CVSS 6.5
CVE-2017-11523 [MEDIUM] CVE-2017-11523 ImageMagick: Endless loop in ReadTXTImage function in coders/txt.c
CVE-2017-11523 ImageMagick: Endless loop in ReadTXTImage function in coders/txt.c
The ReadTXTImage function in coders/txt.c in ImageMagick through 6.9.9-0 and 7.x through 7.0.6-1 allows remote attackers to cause a denial of service (infinite loop) via a crafted file, because the end-of-file condition is not considered.
Upstream bug:
https://github.com/ImageMagick/ImageMagick/issues/591
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/83e0f8ffd7eeb7661b0ff83257da23d24ca7f078
https://github.com/ImageMagick/ImageMagick/commit/a8f9c2aabed37cd6a728532d1aed13ae0f3dfd78
References:
https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=869210
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1474846]
Bugzilla
CVE-2017-11523 ImageMagick: Endless loop in ReadTXTImage function in coders/txt.c [fedora-all]
bugzilla·2017-07-25·CVSS 6.5
CVE-2017-11523 [MEDIUM] CVE-2017-11523 ImageMagick: Endless loop in ReadTXTImage function in coders/txt.c [fedora-all]
CVE-2017-11523 ImageMagick: Endless loop in ReadTXTImage function in coders/txt.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple s
https://bugs.debian.org/869210https://github.com/ImageMagick/ImageMagick/commit/83e0f8ffd7eeb7661b0ff83257da23d24ca7f078https://github.com/ImageMagick/ImageMagick/commit/a8f9c2aabed37cd6a728532d1aed13ae0f3dfd78https://github.com/ImageMagick/ImageMagick/issues/591https://lists.debian.org/debian-lts-announce/2019/05/msg00015.htmlhttps://www.debian.org/security/2017/dsa-4019https://bugs.debian.org/869210https://github.com/ImageMagick/ImageMagick/commit/83e0f8ffd7eeb7661b0ff83257da23d24ca7f078https://github.com/ImageMagick/ImageMagick/commit/a8f9c2aabed37cd6a728532d1aed13ae0f3dfd78https://github.com/ImageMagick/ImageMagick/issues/591https://lists.debian.org/debian-lts-announce/2019/05/msg00015.htmlhttps://www.debian.org/security/2017/dsa-4019
2017-07-22
Published