CVE-2017-12806: High severity ibm data risk manager vulnerability
ImageMagick is vulnerable to a denial of service, caused by a memory exhaustion in the function format8BIM. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to crash.
Other sources
In ImageMagick 7.0.6-6, a memory exhaustion vulnerability was found in the function format8BIM, which allows attackers to cause a denial of service.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this ImageMagick vulnerability?
The vulnerability ID is CVE-2017-12806.
What is the severity level of CVE-2017-12806?
The severity level of CVE-2017-12806 is high.
Which software versions are affected by this vulnerability?
ImageMagick versions 7.0.6-6, 6.9.9, and 6.9.7.4+dfsg-16ubuntu6.7 are affected by this vulnerability.
How can I fix the CVE-2017-12806 vulnerability in ImageMagick?
To fix the CVE-2017-12806 vulnerability in ImageMagick, you can apply the available patches provided by IBM, Red Hat, Ubuntu, and Debian as mentioned in the references.
Where can I find more information about CVE-2017-12806?
You can find more information about CVE-2017-12806 on the following websites: MITRE CVE, Ubuntu Security Notices, and NIST NVD.