CVE-2017-12663
Description
ImageMagick 7.0.6-2 has a memory leak in WriteMAPImage when failing to allocate memory, leading to potential resource exhaustion.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ImageMagick 7.0.6-2 has a memory leak in WriteMAPImage when failing to allocate memory, leading to potential resource exhaustion.
Vulnerability
ImageMagick version 7.0.6-2 contains a memory leak vulnerability in the WriteMAPImage function within coders/map.c [1][2]. When memory allocation for pixels or colormap fails, the function does not properly free previously allocated memory before raising a ThrowWriterException [1]. This results in a memory leak each time the error path is triggered [2].
Exploitation
An attacker can trigger this vulnerability by providing a crafted image file that causes the WriteMAPImage function to fail during memory allocation [2]. The attack requires no authentication and can be performed remotely if the attacker can submit an image to be processed by ImageMagick (e.g., via a web application that uses ImageMagick to convert images) [2]. The exploitation does not require user interaction beyond normal processing of the malicious file [2].
Impact
A successful exploit allows an attacker to cause a memory leak, which can lead to resource exhaustion and denial of service [2]. Repeated exploitation can deplete available memory, making the service unresponsive [2]. The impact is limited to availability; there is no evidence of information disclosure or code execution [1][2].
Mitigation
The vulnerability was fixed in a commit on the ImageMagick master branch [1]. Users should upgrade to a version that includes this fix (version 7.0.6-3 or later) [1]. If immediate upgrade is not possible, users can restrict processing of untrusted image files as a workaround [2].
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
18cpe:2.3:a:imagemagick:imagemagick:7.0.6-2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:imagemagick:imagemagick:7.0.6-2:*:*:*:*:*:*:*
- (no CPE)range: = 7.0.6-2
- osv-coords16 versionspkg:rpm/suse/GraphicsMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/GraphicsMagick&distro=SUSE%20Studio%20Onsite%201.3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3
< 1.2.5-4.78.41.1+ 15 more
- (no CPE)range: < 1.2.5-4.78.41.1
- (no CPE)range: < 1.2.5-4.78.41.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.4.3.6-7.78.37.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.4.3.6-7.78.37.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.4.3.6-7.78.37.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/ImageMagick/ImageMagick/commit/1dc0ac5016f1c4d50b100a086526d6a2453a5444nvdPatchVendor Advisory
- github.com/ImageMagick/ImageMagick/issues/573nvdIssue TrackingPatchVendor Advisory
News mentions
0No linked articles in our index yet.