Description
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read. The portion of the code containing the vulnerability is responsible for printing the IPTC Profile information contained in the image. This vulnerability can be triggered with a specially crafted MIFF file. There is an out-of-bounds buffer dereference because certain increments are never checked.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1159-1 | graphicsmagick security update |
Debian DLA |
DLA-1401-1 | graphicsmagick security update |
Debian DSA |
DSA-4321-1 | graphicsmagick security update |
Ubuntu USN |
USN-4232-1 | GraphicsMagick vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T20:20:05.639Z
Reserved: 2017-11-01T00:00:00.000Z
Link: CVE-2017-16353
No data.
Status : Modified
Published: 2017-11-01T15:29:00.227
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-16353
OpenCVE Enrichment
No data.
Debian DLA
Debian DSA
Ubuntu USN