CVE-2017-11532
Published: 23 July 2017
When ImageMagick 7.0.6-1 processes a crafted file in convert, it can lead to a Memory Leak in the WriteMPCImage() function in coders/mpc.c.
Priority
CVSS 3 base score: 6.5
Status
Package | Release | Status |
---|---|---|
imagemagick Launchpad, Ubuntu, Debian |
artful |
Not vulnerable
(8:6.9.7.4+dfsg-16ubuntu2)
|
bionic |
Not vulnerable
(8:6.9.7.4+dfsg-16ubuntu2)
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
(trusty was ignored)
|
|
upstream |
Needed
|
|
xenial |
Ignored
|
|
zesty |
Ignored
(reached end-of-life)
|
Notes
Author | Note |
---|---|
seth-arnold | This patch may modify an older less sucessful patch that might be required for this one to apply and function |
mdeslaur | 0092-CVE-2017-11532* to 0095-CVE-2017-11532* in unstable 0248-CVE-2017-11532-Fix-WriteMPCImage-memory-leak.patch in wheezy (incomplete?) not fixing memory leak in trusty and xenial |