Heap-based Buffer Over-read in GraphicsMagick Affects Multiple Platforms
CVE-2017-17501
8.8HIGH
What is CVE-2017-17501?
A vulnerability exists in the WriteOnePNGImage function within the coders/png.c file of GraphicsMagick version 1.3.26, which is susceptible to a heap-based buffer over-read. This can be triggered by processing a specially crafted PNG file, potentially allowing an attacker to gain unauthorized access to sensitive information or execute arbitrary code.
