8.8
CVSSv3

CVE-2017-17880

Published: 27/12/2017 Updated: 03/10/2019
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-21, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to a WEBP_DECODER_ABI_VERSION check.

Vulnerable Product Search on Vulmon Subscribe to Product

imagemagick imagemagick 7.0.7-16

Vendor Advisories

Debian Bug report logs - #891291 imagemagick: CVE-2018-7443 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 24 Feb 2018 10:03:01 UTC Severity: important Tags: fixed-up ...
Debian Bug report logs - #891420 imagemagick: CVE-2018-7470 Package: src:imagemagick; Maintainer for src:imagemagick is ImageMagick Packaging Team <pkg-gmagick-im-team@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 25 Feb 2018 13:15:02 UTC Severity: minor Tags: fixed-upstre ...
In ImageMagick 707-16 Q16 x86_64 2017-12-21, there is a stack-based buffer over-read in WriteWEBPImage in coders/webpc, related to a WEBP_DECODER_ABI_VERSION check ...