CVE-2017-16546
published 2017-11-05CVE-2017-16546: The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers…
PriorityP337high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
2.20%
80.5th percentile
The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or possibly have unspecified other impact via a malformed WPG file.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | imagemagick | < imagemagick 8:6.9.9.34+dfsg-3 (bookworm) | imagemagick 8:6.9.9.34+dfsg-3 (bookworm) |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:6.9.9.34+dfsg-3 | 8:6.9.9.34+dfsg-3 |
| imagemagick | imagemagick | >= 0 < 8:6.9.9.34+dfsg-3 | 8:6.9.9.34+dfsg-3 |
| imagemagick | imagemagick | >= 0 < 8:6.9.9.34+dfsg-3 | 8:6.9.9.34+dfsg-3 |
| imagemagick | imagemagick | >= 0 < 8:6.9.9.34+dfsg-3 | 8:6.9.9.34+dfsg-3 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
vendor_debian8.8HIGH
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8r2v-x2w3-6hv7: The ReadWPGImage function in coders/wpg
ghsa_unreviewed·2022-05-13
CVE-2017-16546 [HIGH] CWE-119 GHSA-8r2v-x2w3-6hv7: The ReadWPGImage function in coders/wpg
The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or possibly have unspecified other impact via a malformed WPG file.
OSV
CVE-2017-16546: The ReadWPGImage function in coders/wpg
osv·2017-11-05·CVSS 8.8
CVE-2017-16546 [HIGH] CVE-2017-16546: The ReadWPGImage function in coders/wpg
The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or possibly have unspecified other impact via a malformed WPG file.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2018-06-12
CVE-2017-1000445 ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled certain malformed
image files. If a user or automated system using ImageMagick were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service or possibly execute code with the privileges of
the user invoking the program.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
ImageMagick: Invalid memory allocation in the ReadWPGImage function
vendor_redhat·2017-11-04·CVSS 8.8
CVE-2017-16546 [HIGH] ImageMagick: Invalid memory allocation in the ReadWPGImage function
ImageMagick: Invalid memory allocation in the ReadWPGImage function
The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or possibly have unspecified other impact via a malformed WPG file.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: ImageMagick (Red Hat Enterprise Linux 5) - Will not fix
Package: ImageMagick (Red Hat Enterprise Linux 6) - Will no
Debian
CVE-2017-16546: imagemagick - The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not proper...
vendor_debian·2017·CVSS 8.8
CVE-2017-16546 [HIGH] CVE-2017-16546: imagemagick - The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not proper...
The ReadWPGImage function in coders/wpg.c in ImageMagick 7.0.7-9 does not properly validate the colormap index in a WPG palette, which allows remote attackers to cause a denial of service (use of uninitialized data or invalid memory allocation) or possibly have unspecified other impact via a malformed WPG file.
Scope: local
bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3)
bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3)
forky: resolved (fixed in 8:6.9.9.34+dfsg-3)
sid: resolved (fixed in 8:6.9.9.34+dfsg-3)
trixie: resolved (fixed in 8:6.9.9.34+dfsg-3)
No detection rules found.
No public exploits indexed.
https://github.com/ImageMagick/ImageMagick/commit/2130bf6f89ded32ef0c88a11694f107c52566c53https://github.com/ImageMagick/ImageMagick/commit/e04cf3e9524f50ca336253513d977224e083b816https://github.com/ImageMagick/ImageMagick/issues/851https://usn.ubuntu.com/3681-1/https://www.debian.org/security/2017/dsa-4040https://www.debian.org/security/2017/dsa-4074https://github.com/ImageMagick/ImageMagick/commit/2130bf6f89ded32ef0c88a11694f107c52566c53https://github.com/ImageMagick/ImageMagick/commit/e04cf3e9524f50ca336253513d977224e083b816https://github.com/ImageMagick/ImageMagick/issues/851https://usn.ubuntu.com/3681-1/https://www.debian.org/security/2017/dsa-4040https://www.debian.org/security/2017/dsa-4074
2017-11-05
Published