ImageMagick coders/msl. c Multiple Information Leakage vulnerabilities (CVE-2017-17934)
ImageMagick coders/msl. c Multiple Information Leakage vulnerabilities (CVE-2017-17934)
Release date:
Updated on:
Affected Systems:
ImageMagick ImageMagick 7.0.7-17 Q16 x86_64
Description:
Bugtraq id: 102314
CVE (CAN) ID: CVE-2017-17934
ImageMagick is an open-source image viewing and editing tool on Unix/Linux platforms.
ImageMagick 7.0.7-17 Q16 x86_64 has a memory leakage vulnerability in coders/msl. c, which allows attackers to exploit this vulnerability to obtain sensitive information.
<* Source: future-sec
*>
Suggestion:
Vendor patch:
ImageMagick
-----------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://github.com/ImageMagick/ImageMagick/commit/08278c7cf1c0b4f1da4cdcfaa857ff6b2373a1b2
Https://bugzilla.redhat.com/show_bug.cgi? Id = 1529585
Https://access.redhat.com/security/cve/cve-2017-17934
Http://www.imagemagick.org/
Https://github.com/ImageMagick/ImageMagick/issues/920
Recommended reading:
Use ImageMagick to draw a three-color schematic diagram
In Linux, PHP supports ImageMagick and MagicWandForPHP.
Image Magic with ImageMagick in Linux
Cross-compile ImageMagick in Ubuntu 16.04
Installation of ImageMagick and MagicWand For PHP in Linux
Install ImageMagick and JMagick in Linux
The ImageMagick compiled on Linux system is migrated to another machine.
For details about ImageMagick, click here
ImageMagick: click here