Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2017-13142

Published: 23 August 2017

In ImageMagick before 6.9.9-0 and 7.x before 7.0.6-1, a crafted PNG file could trigger a crash because there was an insufficient check for short files.

Notes

AuthorNote
mdeslaur
0114-Validate-png-file.patch in unstable
0091-Validate-png-file.patch in stretch
0294-CVE-2017-13142-Fix-short-file-check-in-png.c-1-2.patch and
0295-CVE-2017-13142-Fix-short-file-check-in-png.c-2-2.patch in wheezy

Priority

Medium

Cvss 3 Severity Score

6.5

Score breakdown

Status

Package Release Status
imagemagick
Launchpad, Ubuntu, Debian
artful Not vulnerable
(8:6.9.7.4+dfsg-16ubuntu2)
bionic Not vulnerable
(8:6.9.7.4+dfsg-16ubuntu2)
trusty
Released (8:6.7.7.10-6ubuntu3.11)
upstream
Released (8:6.9.7.4+dfsg-15)
xenial
Released (8:6.8.9.9-7ubuntu5.11)
zesty Ignored
(end of life)
Patches:
upstream: https://github.com/ImageMagick/ImageMagick/commit/46e3aabbf8d59a1bdebdbb65acb9b9e0484577d3
upstream: https://github.com/ImageMagick/ImageMagick/commit/aa84944b405acebbeefe871d0f64969b9e9f31ac

Severity score breakdown

Parameter Value
Base score 6.5
Attack vector Network
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H