CVE-2017-14172

NameCVE-2017-14172
DescriptionIn coders/ps.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSImage() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted PSD file, which claims a large "extent" field in the header but does not contain sufficient backing data, is provided, the loop over "length" would consume huge CPU resources, since there is no EOF check inside the loop.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-1131-1
NVD severityhigh (attack range: remote)
Debian Bugs875506

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
imagemagick (PTS)wheezy8:6.7.7.10-5+deb7u4vulnerable
wheezy (security)8:6.7.7.10-5+deb7u18fixed
jessie (security), jessie8:6.8.9.9-5+deb8u11vulnerable
stretch (security), stretch8:6.9.7.4+dfsg-11+deb9u3vulnerable
buster, sid8:6.9.7.4+dfsg-16vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
imagemagicksource(unstable)(unfixed)low875506
imagemagicksourcewheezy8:6.7.7.10-5+deb7u17highDLA-1131-1

Notes

[stretch] - imagemagick <no-dsa> (Minor issue)
[jessie] - imagemagick <no-dsa> (Minor issue)
https://github.com/ImageMagick/ImageMagick/issues/715
ImageMagick-6: https://github.com/ImageMagick/ImageMagick/commit/8598a497e2d1f556a34458cf54b40ba40674734c

Search for package or bug name: Reporting problems