CVE-2017-18252: Medium severity ibm data risk manager vulnerability
An issue was discovered in ImageMagick 7.0.7. The MogrifyImageList function in MagickWand/mogrify.c allows attackers to cause a denial of service (assertion failure and application exit in ReplaceImageInList) via a crafted file.
Other sources
ImageMagick is vulnerable to a denial of service, caused by an error in the MogrifyImageList function in MagickWand/mogrify.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause an assertion failure.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-18252?
CVE-2017-18252 is a vulnerability in ImageMagick 7.0.7 that allows a remote attacker to cause a denial of service.
What is the severity of CVE-2017-18252?
The severity of CVE-2017-18252 is medium with a CVSS score of 6.5.
How does CVE-2017-18252 impact ImageMagick?
CVE-2017-18252 affects the MogrifyImageList function in MagickWand/mogrify.c and can lead to an assertion failure.
How can I fix CVE-2017-18252 in IBM Data Risk Manager 2.0.6?
To fix CVE-2017-18252 in IBM Data Risk Manager 2.0.6, apply the latest patch available from IBM.
How can I fix CVE-2017-18252 in Ubuntu ImageMagick 6.9.9.34?
To fix CVE-2017-18252 in Ubuntu ImageMagick 6.9.9.34, update to version 8:6.9.9.34+dfsg-3 or higher.