CVE-2017-12693 describes a denial-of-service vulnerability in ImageMagick versions 7.0.6-6 and earlier, specifically within the ReadBMPImage function, affecting various ImageMagick installations and Canonical Ubuntu Linux. This medium-severity vulnerability (CVSS 6.5) can be triggered remotely by an unauthenticated attacker through user interaction with a specially crafted BMP file, leading to excessive memory consumption and system instability. While no public exploits, Metasploit modules, or Nuclei templates are available, and there's minimal community discussion or media coverage, its potential for denial of service warrants attention. This CVE is not listed in CISA's KEV catalog, suggesting no known active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0.6-6CPE matchmatch criteria | cpe:2.3:a:imagemagick:imagemagick:7.0.6-6:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:* | ||
16.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:* | ||
17.10CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:* | ||
18.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.