PublicDateAtUSN: 2017-08-30 Candidate: CVE-2017-13769 PublicDate: 2017-08-30 09:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-13769 https://ubuntu.com/security/notices/USN-3681-1 Description: The WriteTHUMBNAILImage function in coders/thumbnail.c in ImageMagick through 7.0.6-10 allows an attacker to cause a denial of service (buffer over-read) by sending a crafted JPEG file. Ubuntu-Description: Notes: mdeslaur> 0308-CVE-2017-13769-Fix-buffer-over-read-in-WriteTHUMBNAILImage-1-of-2.patch and mdeslaur> 0309-CVE-2017-13769-Fix-buffer-over-read-in-WriteTHUMBNAILImage-2-of-2.patch in wheezy mdeslaur> 0250-CVE-2017-13769.patch in jessie mdeslaur> 0102-CVE-2017-13769.patch in unstable Bugs: https://github.com/ImageMagick/ImageMagick/issues/705 https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=878507 Priority: medium Discovered-by: Kirit Sankar Gupta Assigned-to: CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [6.5 MEDIUM] Patches_imagemagick: upstream: https://github.com/ImageMagick/ImageMagick/commit/457e63263de6f732785608504b6e607799ad3dd5 upstream: https://github.com/ImageMagick/ImageMagick/commit/abb9d1322317733b799e8b87b2e346b3038f3260 upstream_imagemagick: released (8:6.9.9.34+dfsg-3) precise/esm_imagemagick: DNE trusty_imagemagick: released (8:6.7.7.10-6ubuntu3.11) trusty/esm_imagemagick: DNE (trusty was released [8:6.7.7.10-6ubuntu3.11]) vivid/ubuntu-core_imagemagick: DNE xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.11) esm-infra/xenial_imagemagick: released (8:6.8.9.9-7ubuntu5.11) zesty_imagemagick: ignored (reached end-of-life) artful_imagemagick: released (8:6.9.7.4+dfsg-16ubuntu2.2) bionic_imagemagick: released (8:6.9.7.4+dfsg-16ubuntu6.2) devel_imagemagick: released (8:6.9.7.4+dfsg-16ubuntu8)