CVE-2017-14989

Description

A use-after-free in RenderFreetype in MagickCore/annotate.c in ImageMagick 7.0.7-4 Q16 allows attackers to crash the application via a crafted font file, because the FT_Done_Glyph function (from FreeType 2) is called at an incorrect place in the ImageMagick code.

Risk Information

Base Score
6.5
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.347

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Imagemagic (x64) 7.0.7Windows
Multiple vulnerabilities affected in Imagemagick 7.0.7Windows
Multiple Vulnerabilities are affected in ImageMagick 7.0.7Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234