6.8
CVSSv2

CVE-2017-11170

Published: 11/07/2017 Updated: 03/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The ReadTGAImage function in coders\tga.c in ImageMagick 7.0.5-6 has a memory leak vulnerability that can cause memory exhaustion via invalid colors data in the header of a TGA or VST file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick 7.0.5-6

Vendor Advisories

Several security issues were fixed in ImageMagick ...
This updates fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed RLE, SVG, PSD, PDB, DPX, MAT, TGA, VST, CIN, DIB, MPC, EPT, JNG, DJVU, JPEG, ICO, PALM or MNG files are pro ...
The ReadTGAImage function in coders\tgac in ImageMagick 705-6 has a memory leak vulnerability that can cause memory exhaustion via invalid colors data in the header of a TGA or VST file ...
Debian Bug report logs - #867825 imagemagick: CVE-2017-11526: CPU exhaustion in ReadOneMNGImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sun, 9 Jul 2017 18:39 ...
Debian Bug report logs - #867798 imagemagick: CVE-2017-11524: assertion failed in WriteBlob Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sun, 9 Jul 2017 15:15:01 ...
Debian Bug report logs - #867894 imagemagick: CVE-2017-11450 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Mon, 10 Jul 2017 11:39:06 UTC Severity: important Tags: ...
Debian Bug report logs - #867810 imagemagick: CVE-2017-11525: memory exhaustion in ReadCINImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sun, 9 Jul 2017 16:42 ...
Debian Bug report logs - #867821 imagemagick: CVE-2017-11530: memory exhaustion in ReadEPTImage in eptc Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sun, 9 Jul 2 ...
Debian Bug report logs - #864273 imagemagick: CVE-2017-9440 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 6 Jun 2017 05:39:02 UTC Severity: normal Tags: fixed-upstr ...
Debian Bug report logs - #867808 [imagemagick] CPU exhaustion in ReadRLEImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sun, 9 Jul 2017 16:42:01 UTC Severity: ...
Debian Bug report logs - #867823 imagemagick: CVE-2017-11529: memory leak in ReadMATImage in matc Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sun, 9 Jul 2017 18 ...
Debian Bug report logs - #867826 imagemagick: CVE-2017-11478: CPU exhaustion in ReadOneDJVUImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sun, 9 Jul 2017 18:4 ...
Debian Bug report logs - #867824 imagemagick: CVE-2017-11505: CPU exhaustion in ReadOneJNGImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sun, 9 Jul 2017 18:39 ...
Debian Bug report logs - #868264 CVE-2017-11141 memory exhaustion in ReadMATImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 12 Jul 2017 21:57:02 UTC Severity: importa ...
Debian Bug report logs - #864274 imagemagick: CVE-2017-9439 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 6 Jun 2017 05:45:01 UTC Severity: normal Tags: fixed-upstr ...
Debian Bug report logs - #867721 CVE-2017-9501 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 8 Jul 2017 21:57:02 UTC Severity: important Tags: fixed-upstream ...
Debian Bug report logs - #868263 CVE-2017-11166 memory exhaustion in ReadXWDImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 12 Jul 2017 21:57:02 UTC Severity: importa ...
Debian Bug report logs - #867367 imagemagick: CVE-2017-10928 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 6 Jul 2017 03:15:01 UTC Severity: important Tags: fixed-u ...
Debian Bug report logs - #867897 imagemagick: CVE-2017-11447 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Mon, 10 Jul 2017 11:42:01 UTC Severity: important Tags: ...
Debian Bug report logs - #867806 imagemagick: CVE-2017-11188: CPU exhaustion in ReadDPXImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sun, 9 Jul 2017 16:39:02 ...
Debian Bug report logs - #867812 imagemagick: CVE-2017-11527: memory exhaustion in ReadDPXImage in dpxc Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sun, 9 Jul 2 ...
Debian Bug report logs - #867896 imagemagick: CVE-2017-11449 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Mon, 10 Jul 2017 11:39:15 UTC Severity: serious Tags: fi ...
Debian Bug report logs - #867778 imagemagick: CVE-2017-9500: assertion failed in ResetImageProfileIterator Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 9 Jul 2017 1 ...
Debian Bug report logs - #867893 imagemagick: CVE-2017-11448 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Mon, 10 Jul 2017 11:39:02 UTC Severity: important Tags: ...
Debian Bug report logs - #868184 CVE-2017-11170 memory exhaustion in ReadTGAImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 12 Jul 2017 21:57:02 UTC Severity: importa ...
Debian Bug report logs - #867811 imagemagick: CVE-2017-11528: memory leak in ReadDIBImage in dibc Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sun, 9 Jul 2017 16 ...