Candidate: CVE-2017-12671 PublicDate: 2017-08-07 21:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-12671 Description: In ImageMagick 7.0.6-3, a missing NULL assignment was found in coders/png.c, leading to an invalid free in the function RelinquishMagickMemory in MagickCore/memory.c, which allows attackers to cause a denial of service. Ubuntu-Description: Notes: mdeslaur> 0124-bad-free-in-RelinquishMagickMemory.patch in unstable mdeslaur> 0096-bad-free-in-RelinquishMagickMemory.patch in stretch mdeslaur> xenial and trusty don't look vulnerable Bugs: https://github.com/ImageMagick/ImageMagick/issues/621 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=870119 Priority: low Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_imagemagick: upstream: https://github.com/ImageMagick/ImageMagick/commit/0de8fd616b92888a7e3d0f640fbb2d397d093944 upstream_imagemagick: released (8:6.9.7.4+dfsg-16) precise/esm_imagemagick: DNE trusty_imagemagick: not-affected (code not present) trusty/esm_imagemagick: DNE (trusty was not-affected [code not present]) vivid/ubuntu-core_imagemagick: DNE xenial_imagemagick: not-affected (code not present) esm-infra/xenial_imagemagick: not-affected (code not present) zesty_imagemagick: ignored (reached end-of-life) artful_imagemagick: not-affected (8:6.9.7.4+dfsg-16ubuntu2) bionic_imagemagick: not-affected (8:6.9.7.4+dfsg-16ubuntu2) devel_imagemagick: not-affected (8:6.9.7.4+dfsg-16ubuntu2)