Heap-Based Buffer Over-Read Vulnerability in GraphicsMagick by Artifex Software
CVE-2017-17912

8.8HIGH

Key Information:

Vendor
CVE Published:
27 December 2017

What is CVE-2017-17912?

In GraphicsMagick version 1.4 snapshot-20171217 Q8, a heap-based buffer over-read was identified in the ReadNewsProfile function located in coders/tiff.c. This vulnerability occurs when the LocaleNCompare function improperly handles data, leading to the reading of heap memory beyond the allocated regions. Such behavior may allow attackers to exploit memory vulnerabilities, potentially causing application instability or leakage of sensitive data.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.