VYPR
Medium severity6.5OSV Advisory· Published May 18, 2018· Updated Jun 17, 2026

CVE-2017-18272

CVE-2017-18272

Description

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-25, there is a use-after-free in ReadOneMNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted MNG image file that is mishandled in an MngInfoDiscardObject call.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • 7.0.7-16, 7.0.7-17, 7.0.7-18, …+ 1 more
    • (no CPE)range: 7.0.7-16, 7.0.7-17, 7.0.7-18, …
    • (no CPE)range: 7.0.7-16 Q16 x86_64 2017-12-25

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.