VYPR
Medium severity6.5OSV Advisory· Published May 18, 2018· Updated Jun 17, 2026

CVE-2017-18273

CVE-2017-18273

Description

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-22, an infinite loop vulnerability was found in the function ReadTXTImage in coders/txt.c, which allows attackers to cause a denial of service (CPU exhaustion) via a crafted image file that is mishandled in a GetImageIndexInList call.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • 7.0.1-0, 7.0.1-1, 7.0.1-10, …+ 2 more
    • (no CPE)range: 7.0.1-0, 7.0.1-1, 7.0.1-10, …
    • (no CPE)range: 7.0.7-16 Q16 x86_64 2017-12-22
    • cpe:2.3:a:imagemagick:imagemagick:7.0.7-16:*:*:*:*:*:*:*
  • cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*+ 3 more
    • cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:17.10:*:*:*:*:*:*:*
    • cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.