CVE-2017-9098
Last modified
CVE-2017-9098 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick code in a long-running server process that converts image data on behalf of multiple users. This is caused by a missing initialization step in the ReadRLEImage function in coders/rle.c.. EPSS estimates a 3.57% chance of exploitation in the next 30 days.
Description
ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick code in a long-running server process that converts image data on behalf of multiple users. This is caused by a missing initialization step in the ReadRLEImage function in coders/rle.c.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Imagemagick | Imagemagick | < 6.9.8-1 |
| Imagemagick | Imagemagick | >= 7.0.0-0, < 7.0.5-2 |
| Graphicsmagick | Graphicsmagick | < 1.3.24 |
| Debian | Debian Linux | 8.0 |
| Debian | Debian Linux | 9.0 |
References
- http://hg.code.sf.net/p/graphicsmagick/code/diff/0a5b75e019b6/coders/rle.cPatch, Third Party Advisory
- http://www.debian.org/security/2017/dsa-3863Third Party Advisory
- http://www.securityfocus.com/bid/98593Third Party Advisory, VDB Entry
- https://github.com/ImageMagick/ImageMagick/commit/1c358ffe0049f768dd49a8a889c1cbf99ac9849bPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00002.htmlMailing List, Third Party Advisory
- https://scarybeastsecurity.blogspot.com/2017/05/bleed-continues-18-byte-file-14k-bounty.htmlExploit, Technical Description, Third Party Advisory
- http://hg.code.sf.net/p/graphicsmagick/code/diff/0a5b75e019b6/coders/rle.cPatch, Third Party Advisory
- http://www.debian.org/security/2017/dsa-3863Third Party Advisory
- http://www.securityfocus.com/bid/98593Third Party Advisory, VDB Entry
- https://github.com/ImageMagick/ImageMagick/commit/1c358ffe0049f768dd49a8a889c1cbf99ac9849bPatch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/08/msg00002.htmlMailing List, Third Party Advisory
- https://scarybeastsecurity.blogspot.com/2017/05/bleed-continues-18-byte-file-14k-bounty.htmlExploit, Technical Description, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-9098?
How severe is CVE-2017-9098?
How do I fix CVE-2017-9098?
Are you affected by CVE-2017-9098?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
