CVE-2017-11524

Description

The WriteBlob function in MagickCore/blob.c in ImageMagick before 6.9.8-10 and 7.x before 7.6.0-0 allows remote attackers to cause a denial of service (assertion failure and application exit) via a crafted file.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.685

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Imagemagic (x64) 7.0.5Windows
Multiple Vulnerabilities are affected in Imagemagic 7.0.5Windows
Multiple Vulnerabilities are affected in ImageMagick 7.0.5Windows
Multiple Vulnerabilities are affected in Imagemagic (x64) 7.0.1-7Windows
Multiple Vulnerabilities are affected in Imagemagic 7.0.1-7Windows
Multiple Vulnerabilities are affected in ImageMagick 7.0.1-7Windows
SUSE-SU-2018:0857-1(SUSE Linux Enterprise Desktop 12-SP2 ) ImageMagick-6.8.8.1-71.47.1.x86_64.rpmLinux
SUSE-SU-2018:0857-1(SUSE Linux Enterprise Desktop 12-SP2 ) ImageMagick-debuginfo-6.8.8.1-71.47.1.x86_64.rpmLinux
SUSE-SU-2018:0857-1(SUSE Linux Enterprise Desktop 12-SP2 ) ImageMagick-debugsource-6.8.8.1-71.47.1.x86_64.rpmLinux
SUSE-SU-2018:0857-1(SUSE Linux Enterprise Desktop 12-SP2 ) libMagick++-6_Q16-3-6.8.8.1-71.47.1.x86_64.rpmLinux
SUSE-SU-2018:0857-1(SUSE Linux Enterprise Desktop 12-SP2 ) libMagick++-6_Q16-3-debuginfo-6.8.8.1-71.47.1.x86_64.rpmLinux
SUSE-SU-2018:0857-1(SUSE Linux Enterprise Desktop 12-SP2 ) libMagickCore-6_Q16-1-6.8.8.1-71.47.1.x86_64.rpmLinux
SUSE-SU-2018:0857-1(SUSE Linux Enterprise Desktop 12-SP2 ) libMagickCore-6_Q16-1-32bit-6.8.8.1-71.47.1.x86_64.rpmLinux
SUSE-SU-2018:0857-1(SUSE Linux Enterprise Desktop 12-SP2 ) libMagickCore-6_Q16-1-debuginfo-6.8.8.1-71.47.1.x86_64.rpmLinux
SUSE-SU-2018:0857-1(SUSE Linux Enterprise Desktop 12-SP2 ) libMagickCore-6_Q16-1-debuginfo-32bit-6.8.8.1-71.47.1.x86_64.rpmLinux
SUSE-SU-2018:0857-1(SUSE Linux Enterprise Desktop 12-SP2 ) libMagickWand-6_Q16-1-6.8.8.1-71.47.1.x86_64.rpmLinux
SUSE-SU-2018:0857-1(SUSE Linux Enterprise Desktop 12-SP2 ) libMagickWand-6_Q16-1-debuginfo-6.8.8.1-71.47.1.x86_64.rpmLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234