CVE-2017-1000476: High severity ibm data risk manager vulnerability
A flaw was found on ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability in the function ReadDDSInfo in coders/dds.c file, which allows attackers to cause a denial of service.
[UPSTREAM BUG] https://github.com/ImageMagick/ImageMagick/issues/867
[UPSTREAM PATCH] https://github.com/ImageMagick/ImageMagick/commit/e5dae180b9236bccd73ce93bfce81e99232a8533
Other sources
ImageMagick 7.0.7-12 Q16, a CPU exhaustion vulnerability was found in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a denial of service.
— Launchpad
ImageMagick is vulnerable to a denial of service, caused by a CPU exhaustion flaw in the function ReadDDSInfo in coders/dds.c, which allows attackers to cause a denial of service. By persuading a victim to open a specailly-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-1000476?
CVE-2017-1000476 is a CPU exhaustion vulnerability in ImageMagick 7.0.7-12 Q16.
How does CVE-2017-1000476 affect ImageMagick?
CVE-2017-1000476 allows attackers to cause a denial of service by exploiting a CPU exhaustion flaw in the ReadDDSInfo function in coders/dds.c.
How severe is CVE-2017-1000476?
CVE-2017-1000476 has a severity rating of 6.5 (high).
Which versions of ImageMagick are affected by CVE-2017-1000476?
The affected versions of ImageMagick are 7.0.7-12 Q16, 8:6.9.7.4+dfsg-16ubuntu2.2, 8:6.9.7.4+dfsg-16ubuntu6.2, 8:6.9.9.34+dfsg-3, 8:6.8.9.9-7ubuntu5.11, and 8:6.7.7.10-6ubuntu3.11.
How can I fix CVE-2017-1000476 in ImageMagick?
To fix CVE-2017-1000476, you should update ImageMagick to version 8:6.9.10.23+dfsg-2.1+deb10u1, 8:6.9.10.23+dfsg-2.1+deb10u5, 8:6.9.11.60+dfsg-1.3+deb11u1, 8:6.9.11.60+dfsg-1.6, or 8:6.9.12.98+dfsg1-2.