CVE-2017-16352 is a heap-based buffer overflow vulnerability in GraphicsMagick 1.3.26, specifically within the DescribeImage() function, affecting Debian and GraphicsMagick installations. This high-severity vulnerability (CVSS 8.8) can be triggered remotely with low complexity by processing a specially crafted MIFF file, potentially leading to complete compromise of confidentiality, integrity, and availability. While not listed on CISA's KEV catalog and lacking significant community discussion or media coverage, an exploit is publicly available on ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.26CPE matchmatch criteria | cpe:2.3:a:graphicsmagick:graphicsmagick:1.3.26:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.