CVE-2017-17914
Description
ImageMagick 7.0.7-16 Q16 contains a denial of service vulnerability via a crafted MNG file triggering an infinite loop in ReadOnePNGImage.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
ImageMagick 7.0.7-16 Q16 contains a denial of service vulnerability via a crafted MNG file triggering an infinite loop in ReadOnePNGImage.
Vulnerability
The vulnerability resides in the function ReadOnePNGImage in coders/png.c in ImageMagick version 7.0.7-16 Q16. When processing a specially crafted MNG image file, the function enters a large loop causing excessive CPU and memory consumption. The issue is triggered by the magick convert command with the crafted file [2].
Exploitation
An attacker can exploit this vulnerability by crafting a malicious MNG image file and tricking a user or automated system into processing it with ImageMagick. No authentication is required; only the ability to deliver the file to the victim (e.g., via email, website upload). The victim running magick convert ./crafted.mng /dev/null will cause ImageMagick to enter an infinite loop in coders/png.c at line 7408, leading to resource exhaustion [2].
Impact
Successful exploitation results in a denial of service (DoS) condition, where the affected system experiences 100% CPU usage and memory consumption, potentially causing the system to become unresponsive or crash [2]. The vulnerability does not lead to code execution or data compromise according to the available references.
Mitigation
The official fix was released in ImageMagick versions after 7.0.7-16. Ubuntu provided updates in USN-3681-1 for affected Ubuntu releases [1]. Users should update to the latest patched version. As a workaround, avoid processing untrusted MNG files with ImageMagick. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog.
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
15- Range: = 7.0.7-16 Q16
- osv-coords14 versionspkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2011%20SP4pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2011%20SP4pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2011%20SP4pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP3pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP2pkg:rpm/suse/ImageMagick&distro=SUSE%20Linux%20Enterprise%20Workstation%20Extension%2012%20SP3
< 6.8.8.1-71.33.1+ 13 more
- (no CPE)range: < 6.8.8.1-71.33.1
- (no CPE)range: < 6.8.8.1-71.33.1
- (no CPE)range: < 6.4.3.6-7.78.29.2
- (no CPE)range: < 6.8.8.1-71.33.1
- (no CPE)range: < 6.8.8.1-71.33.1
- (no CPE)range: < 6.8.8.1-71.33.1
- (no CPE)range: < 6.4.3.6-7.78.29.2
- (no CPE)range: < 6.8.8.1-71.33.1
- (no CPE)range: < 6.8.8.1-71.33.1
- (no CPE)range: < 6.4.3.6-7.78.29.2
- (no CPE)range: < 6.8.8.1-71.33.1
- (no CPE)range: < 6.8.8.1-71.33.1
- (no CPE)range: < 6.8.8.1-71.33.1
- (no CPE)range: < 6.8.8.1-71.33.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- github.com/ImageMagick/ImageMagick/issues/908nvdIssue TrackingVendor Advisory
- lists.debian.org/debian-lts-announce/2018/01/msg00000.htmlnvdMailing ListThird Party Advisory
- usn.ubuntu.com/3681-1/nvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/05/msg00015.htmlnvd
- lists.debian.org/debian-lts-announce/2020/09/msg00007.htmlnvd
News mentions
0No linked articles in our index yet.