Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2017-9098

Published: 19 May 2017

ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick code in a long-running server process that converts image data on behalf of multiple users. This is caused by a missing initialization step in the ReadRLEImage function in coders/rle.c.

Notes

AuthorNote
mdeslaur
This is 0216-CVE-2017-9098-use-of-uninitialized-memory-in-RLE-dec.patch

Priority

Medium

Cvss 3 Severity Score

7.5

Score breakdown

Status

Package Release Status
imagemagick
Launchpad, Ubuntu, Debian
trusty
Released (8:6.7.7.10-6ubuntu3.7)
upstream
Released (7.0.5-2)
xenial
Released (8:6.8.9.9-7ubuntu5.7)
yakkety
Released (8:6.8.9.9-7ubuntu8.6)
zesty
Released (8:6.9.7.4+dfsg-3ubuntu1.1)
Patches:
upstream: https://github.com/ImageMagick/ImageMagick/commit/1c358ffe0049f768dd49a8a889c1cbf99ac9849b

Severity score breakdown

Parameter Value
Base score 7.5
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N