6.5
CVSSv3

CVE-2017-11533

Published: 23/07/2017 Updated: 03/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteUILImage() function in coders/uil.c.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick 7.0.6-1

Vendor Advisories

Several security issues were fixed in ImageMagick ...
This update fixes several vulnerabilities in imagemagick, a graphical software suite Various memory handling problems or issues about incomplete input sanitizing would result in denial of service or memory disclosure For the oldstable distribution (jessie), these problems have been fixed in version 8:6899-5+deb8u12 We recommend that you upgra ...
When ImageMagick 706-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteUILImage() function in coders/uilc ...
Debian Bug report logs - #869210 imagemagick: CVE-2017-11523: endless loop in ReadTXTImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Fri, 21 Jul 2017 15:39:02 U ...
Debian Bug report logs - #869830 imagemagick: CVE-2017-13145 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Wed, 26 Jul 2017 20:51:02 UTC Severity: important Tags: ...
Debian Bug report logs - #869827 CVE-2017-11535: heap based overflow in psc Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Wed, 26 Jul 2017 20:30:01 UTC Severity: ...
Debian Bug report logs - #869712 CVE-2017-11537: palm fpe Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Tue, 25 Jul 2017 20:36:01 UTC Severity: important Tags: sec ...
Debian Bug report logs - #869831 CVE-2017-11536 memory leak in jp2 coder Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Wed, 26 Jul 2017 21:03:02 UTC Severity: impo ...
Debian Bug report logs - #869715 imagemagick: CVE-2017-12431: use after free in ReadWMFImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Tue, 25 Jul 2017 20:45:09 ...
Debian Bug report logs - #869721 imagemagick: CVE-2017-12664 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Tue, 25 Jul 2017 21:33:01 UTC Severity: important Tags: ...
Debian Bug report logs - #869711 CVE-2017-11534: wmf memory leak Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Tue, 25 Jul 2017 20:33:04 UTC Severity: important Ta ...
Debian Bug report logs - #869726 CVE-2017-11532: memory leak in coders/mpcc Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Tue, 25 Jul 2017 21:57:02 UTC Severity: ...
Debian Bug report logs - #869725 CVE-2017-11531: Memory Leak in coders/histogramc Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Tue, 25 Jul 2017 21:51:02 UTC Sev ...
Debian Bug report logs - #869727 imagemagick: CVE-2017-12430: Memory exhaustion in mpc coder Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Tue, 25 Jul 2017 22:06:01 ...
Debian Bug report logs - #869834 CVE-2017-11533: heap buffer overflow in uil coder Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Wed, 26 Jul 2017 21:15:05 UTC Seve ...
Debian Bug report logs - #867748 imagemagick: CVE-2017-10995 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 9 Jul 2017 08:15:01 UTC Severity: important Tags: fixed-u ...
Debian Bug report logs - #869796 imagemagick: CVE-2017-12642 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Wed, 26 Jul 2017 14:15:02 UTC Severity: important Tags: ...
Debian Bug report logs - #868950 imagemagick: CVE-2017-11446 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Wed, 19 Jul 2017 19:09:01 UTC Severity: important Tags: fixed-u ...
Debian Bug report logs - #869722 Imagemagick: memory leak in quantize Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Tue, 25 Jul 2017 21:33:07 UTC Severity: importa ...
Debian Bug report logs - #867778 imagemagick: CVE-2017-9500: assertion failed in ResetImageProfileIterator Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 9 Jul 2017 1 ...
Debian Bug report logs - #869728 imagemagick: CVE-2017-13144 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Tue, 25 Jul 2017 22:09:01 UTC Severity: serious Tags: se ...
Debian Bug report logs - #885340 CVE-2017-17504 Package: imagemagick; Maintainer for imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Source for imagemagick is src:imagemagick (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 26 Dec 2017 12:51:05 ...
Debian Bug report logs - #885125 imagemagick: CVE-2017-17879: heap-buffer-overflow in ReadOneMNGImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 24 Dec 2017 09:45: ...