CVE-2017-18254: Medium severity ibm data risk manager vulnerability
An issue was discovered in ImageMagick 7.0.7. A memory leak vulnerability was found in the function WriteGIFImage in coders/gif.c, which allow remote attackers to cause a denial of service via a crafted file.
Other sources
ImageMagick is vulnerable to a denial of service, caused by a memory leak in the WriteGIFImage function in coders/gif.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause a denial of service condition.
— IBM
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2017-18254.
What is the affected software?
The affected software includes IBM Data Risk Manager, ImageMagick on Ubuntu, and ImageMagick on Debian.
What is the severity of CVE-2017-18254?
The severity of CVE-2017-18254 is medium with a CVSS score of 6.5.
How can I fix CVE-2017-18254?
To fix CVE-2017-18254, you can apply the respective patches provided by the vendors, such as IBM, Ubuntu, and Debian, or upgrade to the recommended versions of ImageMagick.
Where can I find more information about CVE-2017-18254?
You can find more information about CVE-2017-18254 on the GitHub page of ImageMagick, Ubuntu security notices, and the CVE/CWE details.