Excessive Iteration Affecting imagemagick package, versions <8:6.9.9.34+dfsg-3
Snyk CVSS
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN11-IMAGEMAGICK-531869
- published 7 Sep 2017
- disclosed 7 Sep 2017
Introduced: 7 Sep 2017
CVE-2017-14174 Open this link in a new tabHow to fix?
Upgrade Debian:11
imagemagick
to version 8:6.9.9.34+dfsg-3 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream imagemagick
package and not the imagemagick
package as distributed by Debian
.
See How to fix?
for Debian:11
relevant fixed versions and status.
In coders/psd.c in ImageMagick 7.0.7-0 Q16, a DoS in ReadPSDLayersInternal() due to lack of an EOF (End of File) check might cause huge CPU consumption. When a crafted PSD file, which claims a large "length" field in the header but does not contain sufficient backing data, is provided, the loop over "length" would consume huge CPU resources, since there is no EOF check inside the loop.
References
- https://security-tracker.debian.org/tracker/CVE-2017-14174
- https://lists.debian.org/debian-lts-announce/2019/05/msg00015.html
- https://security.gentoo.org/glsa/201711-07
- https://github.com/ImageMagick/ImageMagick/commit/04a567494786d5bb50894fc8bb8fea0cf496bea8
- https://github.com/ImageMagick/ImageMagick/commit/f68a98a9d385838a1c73ec960a14102949940a64
- https://github.com/ImageMagick/ImageMagick/issues/714
- https://lists.debian.org/debian-lts-announce/2020/09/msg00007.html
- http://people.ubuntu.com/~ubuntu-security/cve/CVE-2017-14174
- https://usn.ubuntu.com/3681-1/