6.5
CVSSv3

CVE-2017-11352

Published: 17/07/2017 Updated: 28/04/2021
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In ImageMagick prior to 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick

debian debian linux 8.0

canonical ubuntu linux 14.04

canonical ubuntu linux 16.04

canonical ubuntu linux 17.10

canonical ubuntu linux 18.04

Vendor Advisories

Several security issues were fixed in ImageMagick ...
Several security issues were fixed in ImageMagick ...
This updates fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed RLE, SVG, PSD, PDB, DPX, MAT, TGA, VST, CIN, DIB, MPC, EPT, JNG, DJVU, JPEG, ICO, PALM or MNG files are pro ...
This update fixes several vulnerabilities in imagemagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed image files are processed For the oldstable distribution (jessie), these problems have been fixed in versio ...
In ImageMagick before 705-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rlec NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144 ...
Debian Bug report logs - #876488 imagemagick: CVE-2017-14682: Heap buffer overflow in GetNextToken() Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Fri, 22 Sep 2017 18:24:0 ...
Debian Bug report logs - #878527 imagemagick: CVE-2017-14607 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 11:57:02 UTC Severity: serious Tags: confirmed ...
Debian Bug report logs - #876097 imagemagick: CVE-2017-14224: Heap buffer overflow in WritePCXImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 18 Sep 2017 12:33:01 ...
Debian Bug report logs - #881392 imagemagick: CVE-2017-16546 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 11 Nov 2017 09:03:02 UTC Severity: grave Tags: confirmed, ...
Debian Bug report logs - #872373 CVE-2017-12877 Package: imagemagick; Maintainer for imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Source for imagemagick is src:imagemagick (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Wed, 16 Aug 2017 21:12:01 ...
Debian Bug report logs - #868469 imagemagick: CVE-2017-11352 (Incomplete fix for CVE-2017-9144) Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 15 Jul 2017 19:45:01 UTC ...
Debian Bug report logs - #873134 imagemagick: CVE-2017-12983 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 24 Aug 2017 19:27:01 UTC Severity: serious Tags: confirmed ...
Debian Bug report logs - #878562 imagemagick: CVE-2017-14989 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 16:51:05 UTC Severity: serious Tags: confirmed ...
Debian Bug report logs - #869728 imagemagick: CVE-2017-13144 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Tue, 25 Jul 2017 22:09:01 UTC Severity: serious Tags: se ...
Debian Bug report logs - #873099 imagemagick: CVE-2017-13134 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Thu, 24 Aug 2017 14:57:02 UTC Severity: serious Tags: confirmed ...
Debian Bug report logs - #878508 imagemagick: CVE-2017-13758 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 09:03:02 UTC Severity: serious Tags: confirmed ...
Debian Bug report logs - #878507 imagemagick: CVE-2017-13769 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 08:57:02 UTC Severity: serious Tags: confirmed ...
Debian Bug report logs - #878578 imagemagick: CVE-2017-15277 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 14 Oct 2017 18:51:02 UTC Severity: serious Tags: confirmed ...
In ImageMagick before 705-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rlec This is caused by an incomplete fix of CVE-2017-9144 ...