CVE-2017-12664
Description
ImageMagick 7.0.6-2 has a memory leak in WritePALMImage that leads to resource exhaustion and potential denial-of-service.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ImageMagick 7.0.6-2 has a memory leak in WritePALMImage that leads to resource exhaustion and potential denial-of-service.
Vulnerability
ImageMagick 7.0.6-2 contains a memory leak vulnerability in WritePALMImage within coders/palm.c. When converting an image to the PALM format, the function fails to properly free allocated memory for certain internal buffers, specifically QuantizeInfo and grayscale quantisation structures, under specific compression conditions. The issue affects ImageMagick version 7.0.6-2 [1][2].
Exploitation
An attacker can trigger the memory leak by providing a crafted input image file and using the convert command to write a PALM output (e.g., ./magick convert $FILE out.palm). No authentication or special privileges are required beyond the ability to run ImageMagick with a malicious file. The leak occurs during the normal image-processing pipeline, requiring no user interaction beyond executing the conversion command [1][2].
Impact
Successfully exploiting this vulnerability results in progressive memory consumption, potentially leading to resource exhaustion and denial-of-service on the system running ImageMagick. The leak does not enable arbitrary code execution or data corruption, but repeated conversions could exhaust available memory, causing software or system crashes [1][2].
Mitigation
The fix was committed to the ImageMagick repository on 2017-08-07 and is included in versions after 7.0.6-2. Users should upgrade to a patched release (e.g., 7.0.6-3 or later). No EOL or KEV listing is noted. If upgrading is not immediately possible, avoid processing untrusted image files with ImageMagick until the patch is applied [1][2].
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
16cpe:2.3:a:imagemagick:imagemagick:7.0.6-2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:imagemagick:imagemagick:7.0.6-2:*:*:*:*:*:*:*
- (no CPE)range: = 7.0.6-2
- osv-coords14 versionspkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3
< 6.8.8.1-71.42.1+ 13 more
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.4.3.6-7.78.34.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.4.3.6-7.78.34.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.4.3.6-7.78.34.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
- (no CPE)range: < 6.8.8.1-71.42.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- github.com/ImageMagick/ImageMagick/commit/0417cea1b6d72f90bd4f1f573f91e42a8ba66a89nvdPatchVendor Advisory
- github.com/ImageMagick/ImageMagick/issues/574nvdIssue TrackingPatchVendor Advisory
News mentions
0No linked articles in our index yet.