383
VMScore

CVE-2017-11639

Published: 26/07/2017 Updated: 03/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a heap-based buffer over-read in the WriteCIPImage() function in coders/cip.c, related to the GetPixelLuma function in MagickCore/pixel-accessor.h.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick 7.0.6-1

Vendor Advisories

Several security issues were fixed in ImageMagick ...
This update fixes several vulnerabilities in imagemagick, a graphical software suite Various memory handling problems or issues about incomplete input sanitizing would result in denial of service or memory disclosure For the oldstable distribution (jessie), these problems have been fixed in version 8:6899-5+deb8u12 We recommend that you upgra ...
Debian Bug report logs - #869210 imagemagick: CVE-2017-11523: endless loop in ReadTXTImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Fri, 21 Jul 2017 15:39:02 U ...
Debian Bug report logs - #870118 imagemagick: CVE-2017-12676 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Jul 2017 21:39:02 UTC Severity: important Tags: ...
Debian Bug report logs - #870115 imagemagick: CVE-2017-12565: memory leak in ReadOneJNGImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Jul 2017 21:36:01 ...
Debian Bug report logs - #870119 CVE-2017-12671 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Jul 2017 21:39:07 UTC Severity: important Tags: security, ups ...
Debian Bug report logs - #870065 CVE-2017-11639 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Jul 2017 12:06:05 UTC Severity: important Tags: security, ups ...
Debian Bug report logs - #870120 CVE-2017-11539 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Jul 2017 21:45:02 UTC Severity: important Tags: security, ups ...
Debian Bug report logs - #870108 imagemagick: CVE-2017-12641 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Jul 2017 20:45:01 UTC Severity: important Tags: ...
Debian Bug report logs - #870116 imagemagick: CVE-2017-13141 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Jul 2017 21:36:09 UTC Severity: important Tags: ...
Debian Bug report logs - #870111 imagemagick: CVE-2017-13140 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Jul 2017 20:51:01 UTC Severity: important Tags: ...
Debian Bug report logs - #870105 imagemagick: CVE-2017-13142 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Jul 2017 20:33:02 UTC Severity: important Tags: ...
Debian Bug report logs - #870106 imagemagick: CVE-2017-12640 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Jul 2017 20:39:01 UTC Severity: important Tags: ...
Debian Bug report logs - #869834 CVE-2017-11533: heap buffer overflow in uil coder Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Wed, 26 Jul 2017 21:15:05 UTC Seve ...
Debian Bug report logs - #867748 imagemagick: CVE-2017-10995 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 9 Jul 2017 08:15:01 UTC Severity: important Tags: fixed-u ...
Debian Bug report logs - #870109 imagemagick: CVE-2017-13139 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Jul 2017 20:45:07 UTC Severity: important Tags: ...
Debian Bug report logs - #870117 imagemagick: CVE-2017-12673 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Jul 2017 21:36:15 UTC Severity: important Tags: ...
Debian Bug report logs - #870107 imagemagick: CVE-2017-12643: memory exhaustion in ReadOneJNGImage in pngc Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Ju ...
Debian Bug report logs - #870067 CVE-2017-11640 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Sat, 29 Jul 2017 12:09:04 UTC Severity: important Tags: security, ups ...
Debian Bug report logs - #869728 imagemagick: CVE-2017-13144 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Bastien ROUCARIES <roucariesbastien@gmailcom> Date: Tue, 25 Jul 2017 22:09:01 UTC Severity: serious Tags: se ...
Debian Bug report logs - #885340 CVE-2017-17504 Package: imagemagick; Maintainer for imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Source for imagemagick is src:imagemagick (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 26 Dec 2017 12:51:05 ...
Debian Bug report logs - #885125 imagemagick: CVE-2017-17879: heap-buffer-overflow in ReadOneMNGImage Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 24 Dec 2017 09:45: ...