CVE-2017-14997: Integer Underflow
Published Oct 3, 2017
·Updated
GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c.
Affected Software
4 affected componentsFixes available
GraphicsMagick Graphicsmagick=1.3.26
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/graphicsmagick
1.4+really1.3.36+hg16481-2+deb11u11.4+really1.3.40-4+deb12u11.4+really1.3.45+hg17696-11.4+really1.3.46-2
Remediation
Patch Available
Event History
Oct 3, 2017
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:56 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:56 PM
DescriptionAffected Software
Data Sourced
via Launchpad·08:56 PM
Description
Frequently Asked Questions
1
What is the vulnerability CVE-2017-14997?
The vulnerability CVE-2017-14997 is a denial of service (excessive memory allocation) vulnerability in GraphicsMagick 1.3.26.
2
How does the vulnerability CVE-2017-14997 affect GraphicsMagick?
The vulnerability CVE-2017-14997 allows remote attackers to cause a denial of service by exploiting an integer underflow in ReadPICTImage in coders/pict.c.
3
What is the severity of vulnerability CVE-2017-14997?
The severity of vulnerability CVE-2017-14997 is high with a CVSS score of 6.5.
4
Is my version of GraphicsMagick affected by vulnerability CVE-2017-14997?
GraphicsMagick version 1.3.26 is affected by vulnerability CVE-2017-14997.
5
How can I fix vulnerability CVE-2017-14997 in GraphicsMagick?
To fix vulnerability CVE-2017-14997 in GraphicsMagick, you should update to a patched version of the software.