UBUNTU-CVE-2017-16547
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-16547
UBUNTU-CVE-2017-16547
Summary:
Details: The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of service (negative strncpy and application crash) or possibly have unspecified other impact via a crafted file.
References: https://ubuntu.com/security/CVE-2017-16547, http://hg.code.sf.net/p/graphicsmagick/code/rev/785758bbbfcc, https://sourceforge.net/p/graphicsmagick/bugs/517/, https://ubuntu.com/security/notices/USN-4248-1, https://www.cve.org/CVERecord?id=CVE-2017-16547
Affected packages
Package
Name: graphicsmagick
Purl: pkg:deb/ubuntu/[email protected]+esm5?arch=source&distro=trusty/esm
Affected ranges
Type: ECOSYSTEM
Events:
