CVE-2017-12805: High severity ibm data risk manager vulnerability
ImageMagick is vulnerable to a denial of service, caused by an error in the function ReadTIFFImage. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
Other sources
In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the function ReadTIFFImage, which allows attackers to cause a denial of service.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-12805?
CVE-2017-12805 is a memory exhaustion vulnerability found in the function ReadTIFFImage in ImageMagick 7.0.6-6.
How does CVE-2017-12805 affect ImageMagick?
CVE-2017-12805 can cause a denial of service in ImageMagick by crashing the application.
How can the CVE-2017-12805 vulnerability be exploited?
The CVE-2017-12805 vulnerability can be exploited by persuading a victim to open a specially-crafted file.
What is the severity of CVE-2017-12805?
CVE-2017-12805 has a severity score of 7.5, classified as high.
How can I fix CVE-2017-12805 in ImageMagick?
To fix CVE-2017-12805 in ImageMagick, you should apply the available patches or updates provided by the vendor, such as IBM, Red Hat, Ubuntu, or Debian.