ImageMagick CVE-2017-18029 Information Disclosure Vulnerability

ImageMagick is prone to an information-disclosure vulnerability.

An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks. Failed exploit attempts may result in denial-of-service conditions.

ImageMagick 7.0.6-10 Q16 is vulnerable; other versions may also be affected.


Bugtraq ID: 102519
Class: Failure to Handle Exceptional Conditions
CVE: CVE-2017-18029

Remote: Yes
Local: No
Published: Jan 12 2018 12:00AM
Updated: Jan 12 2018 12:00AM
Credit: ADLab of Venustech
Vulnerable: Redhat Enterprise Linux 7
Redhat Enterprise Linux 6
+ Trustix Secure Enterprise Linux 2.0
+ Trustix Secure Linux 2.2
+ Trustix Secure Linux 2.1
+ Trustix Secure Linux 2.0
Redhat Enterprise Linux 5
ImageMagick ImageMagick 7.0.6-10 Q16

Not Vulnerable:


The researcher has created a proof-of-concept to demonstrate the issue. Please see the references for more information.

Related Posts