CVE-2017-14733: Medium severity GraphicsMagick Graphicsmagick vulnerability
Last updated 25 August 2025
Other sources
ReadRLEImage in coders/rle.c in GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-14733.
What is the severity of CVE-2017-14733?
The severity of CVE-2017-14733 is medium, with a severity value of 6.5.
How does GraphicsMagick 1.3.26 handle RLE headers that specify too few colors?
GraphicsMagick 1.3.26 mishandles RLE headers that specify too few colors, leading to a denial of service (heap-based buffer over-read and application crash).
What is the affected software for CVE-2017-14733?
The affected software for CVE-2017-14733 includes GraphicsMagick 1.3.26, Debian Linux 8.0, and Debian Linux 9.0.
How can I fix CVE-2017-14733?
To fix CVE-2017-14733, you should upgrade to a patched version of the software. For example, Ubuntu provides a fix in version 1.3.23-1ubuntu0.4 of GraphicsMagick.