CVE-2017-16353 is a memory information disclosure vulnerability in GraphicsMagick 1.3.26, specifically within the DescribeImage function, affecting Debian and GraphicsMagick products. This heap-based buffer over-read can be triggered by a specially crafted MIFF file, leading to the disclosure of IPTC Profile information. Rated Medium severity (CVSS 6.5), it requires user interaction (UI:R) but can be exploited remotely (AV:N) with low complexity (AC:L), potentially leading to high confidentiality impact (C:H). While not actively exploited in the wild (KEV: No) and lacking significant community discussion or media coverage, public exploit code (EDB-43111) is available, indicating a potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.3.26CPE matchmatch criteria | cpe:2.3:a:graphicsmagick:graphicsmagick:1.3.26:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.