High severity8.8NVD Advisory· Published Jul 18, 2017· Updated May 13, 2026
CVE-2017-11403
CVE-2017-11403
Description
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 has an out-of-order CloseBlob call, resulting in a use-after-free via a crafted file.
Affected products
1- cpe:2.3:a:graphicsmagick:graphicsmagick:1.3.26:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- hg.code.sf.net/p/graphicsmagick/code/rev/d0a76868ca37nvdIssue TrackingPatchThird Party Advisory
- blogs.gentoo.org/ago/2017/07/12/graphicsmagick-use-after-free-in-closeblob-blob-c/nvdPatchThird Party AdvisoryVDB Entry
- lists.debian.org/debian-lts-announce/2018/08/msg00002.htmlnvd
- usn.ubuntu.com/4206-1/nvd
- www.debian.org/security/2018/dsa-4321nvd
News mentions
0No linked articles in our index yet.