UBUNTU-CVE-2017-16353
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-16353
UBUNTU-CVE-2017-16353
Summary:
Details: GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read. The portion of the code containing the vulnerability is responsible for printing the IPTC Profile information contained in the image. This vulnerability can be triggered with a specially crafted MIFF file. There is an out-of-bounds buffer dereference because certain increments are never checked.
References: https://ubuntu.com/security/CVE-2017-16353, http://hg.graphicsmagick.org/hg/GraphicsMagick?cmd=changeset;node=e4e1c2a581d8, https://blogs.securiteam.com/index.php/archives/3494, https://ubuntu.com/security/notices/USN-4232-1, https://www.cve.org/CVERecord?id=CVE-2017-16353
Affected packages
Package
Name: graphicsmagick
Purl: pkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
