5.5
CVSSv3

CVE-2017-10995

Published: 07/07/2017 Updated: 03/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

The mng_get_long function in coders/png.c in ImageMagick 7.0.6-0 allows remote malicious users to cause a denial of service (heap-based buffer over-read and application crash) via a crafted MNG image.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick 7.0.6-0

Vendor Advisories

Several security issues were fixed in ImageMagick ...
This update fixes several vulnerabilities in imagemagick, a graphical software suite Various memory handling problems or issues about incomplete input sanitizing would result in denial of service or memory disclosure For the oldstable distribution (jessie), these problems have been fixed in version 8:6899-5+deb8u12 We recommend that you upgra ...
Debian Bug report logs - #867748 imagemagick: CVE-2017-10995 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 9 Jul 2017 08:15:01 UTC Severity: important Tags: fixed-u ...
Debian Bug report logs - #885340 CVE-2017-17504 Package: imagemagick; Maintainer for imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Source for imagemagick is src:imagemagick (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 26 Dec 2017 12:51:05 ...
Debian Bug report logs - #885125 imagemagick: CVE-2017-17879: heap-buffer-overflow in ReadOneMNGImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 24 Dec 2017 09:45: ...
The mng_get_long function in coders/pngc in ImageMagick 706-0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted MNG image ...