CVE-2017-17880Out-of-bounds Read in Imagemagick

CWE-125Out-of-bounds Read7 documents6 sources
Severity
8.8HIGHNVD
EPSS
0.4%
top 38.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedDec 27
Latest updateMay 13

Description

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to a WEBP_DECODER_ABI_VERSION check.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages3 packages

debiandebian/imagemagick< imagemagick 8:6.9.9.39+dfsg-1 (bookworm)
Debianimagemagick/imagemagick< 8:6.9.9.39+dfsg-1+3

🔴Vulnerability Details

2
GHSA
GHSA-665c-9q2w-85pg: In ImageMagick 72022-05-13
OSV
CVE-2017-17880: In ImageMagick 72017-12-27

📋Vendor Advisories

2
Red Hat
ImageMagick: stack-based buffer over-read in WriteWEBPImage in coders/webp.c2017-12-22
Debian
CVE-2017-17880: imagemagick - In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a stack-based buffer ove...2017

💬Community

2
Bugzilla
CVE-2017-17880 ImageMagick: stack-based buffer over-read in WriteWEBPImage in coders/webp.c [fedora-all]2017-12-27
Bugzilla
CVE-2017-17880 ImageMagick: stack-based buffer over-read in WriteWEBPImage in coders/webp.c2017-12-27