CVE-2017-14505

Severity CVSS v4.0:
Pending analysis
Type:
CWE-476 NULL Pointer Dereference
Publication date:
17/09/2017
Last modified:
20/04/2025

Description

DrawGetStrokeDashArray in wand/drawing-wand.c in ImageMagick 7.0.7-1 mishandles certain NULL arrays, which allows attackers to perform Denial of Service (NULL pointer dereference and application crash in AcquireQuantumMemory within MagickCore/memory.c) by providing a crafted Image File as input.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:imagemagick:imagemagick:7.0.7-1:*:*:*:*:*:*:*