Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2017-10995

Published: 7 July 2017

The mng_get_long function in coders/png.c in ImageMagick 7.0.6-0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted MNG image.

Notes

AuthorNote
sbeattie
reproducer in github report
mdeslaur
This is 0244-CVE-2017-10995-Fix-denial-of-service-in-mng_get_long.patch in wheezy
this is 0272-CVE-2017-10995.patch in jessie

Priority

Low

Cvss 3 Severity Score

5.5

Score breakdown

Status

Package Release Status
imagemagick
Launchpad, Ubuntu, Debian
artful Not vulnerable
(8:6.9.7.4+dfsg-16ubuntu2)
bionic Not vulnerable
(8:6.9.7.4+dfsg-16ubuntu2)
trusty
Released (8:6.7.7.10-6ubuntu3.11)
upstream Needed

xenial
Released (8:6.8.9.9-7ubuntu5.11)
yakkety Ignored
(end of life)
zesty Not vulnerable
(8:6.9.7.4+dfsg-3ubuntu1.2)
Patches:
upstream: https://github.com/ImageMagick/ImageMagick/commit/24430226caf7eb468b4180f2883b2563e8cc1b23
upstream: https://github.com/ImageMagick/ImageMagick/commit/1fdc09dc8f9522f07f5f501fe8453765ad82556c

Severity score breakdown

Parameter Value
Base score 5.5
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H