CVE-2017-18271: High severity ibm data risk manager vulnerability
A flaw was found in ImageMagick 7.0.7-16 Q16 x8664 2017-12-22, an infinite loop vulnerability was found in the function ReadMIFFImage in coders/miff.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted MIFF image file.
References: https://github.com/ImageMagick/ImageMagick/issues/911
Patch: https://github.com/ImageMagick/ImageMagick/commit/7523250e2664028aa1d8f02d2d7ae49c769a851e
Other sources
ImageMagick is vulnerable to a denial of service, caused by an infinite loop in the function ReadMIFFImage in coders/miff.c. By persuading a victim to open a specially-crafted file, a remote attacker could exploit this vulnerability to cause the application to consume all available CPU resources.
— IBM
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2017-18271?
CVE-2017-18271 is a vulnerability in ImageMagick that allows a remote attacker to cause a denial of service by triggering an infinite loop.
What is the severity of CVE-2017-18271?
The severity of CVE-2017-18271 is high, with a severity value of 6.5.
Which version of ImageMagick is affected by CVE-2017-18271?
ImageMagick version 7.0.7-16 is affected by CVE-2017-18271.
How can I fix CVE-2017-18271?
To fix CVE-2017-18271, you should apply the latest patches provided by the vendor or update to a patched version of ImageMagick.
Where can I find more information about CVE-2017-18271?
You can find more information about CVE-2017-18271 on the official GitHub page for ImageMagick and the security advisory pages for Debian and Ubuntu.