CVE-2017-14649: Medium severity GraphicsMagick Graphicsmagick vulnerability
Last updated 25 August 2025
Other sources
ReadOneJNGImage in coders/png.c in GraphicsMagick version 1.3.26 does not properly validate JNG data, leading to a denial of service (assertion failure in magick/pixelcache.c, and application crash).
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-14649?
CVE-2017-14649 is a vulnerability in GraphicsMagick version 1.3.26 that allows an attacker to cause a denial of service by sending malicious JNG data.
How does CVE-2017-14649 impact GraphicsMagick?
CVE-2017-14649 can cause GraphicsMagick to crash due to an assertion failure in the pixel_cache.c file.
What is the severity of CVE-2017-14649?
The severity of CVE-2017-14649 is medium with a severity value of 5.5.
How do I fix the CVE-2017-14649 vulnerability in GraphicsMagick?
To fix the CVE-2017-14649 vulnerability, you should update your GraphicsMagick installation to a version that is not affected by the vulnerability.
Where can I find more information about CVE-2017-14649?
You can find more information about CVE-2017-14649 on the following references: [link1], [link2], [link3].