Heap-based buffer overflow in the PushQuantumPixel function in ImageMagick before 6.9.7-3 and 7.x before 7.0.4-3 allows remote attackers to cause a denial of service (application crash) via a crafted TIFF file.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "7.0.1-0"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.1-1"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.1-2"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.1-3"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.1-4"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.1-5"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.1-6"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.1-7"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.1-8"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.1-9"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.1-10"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.2-0"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.2-1"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.2-2"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.2-3"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.2-4"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.2-5"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.2-6"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.2-7"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.2-8"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.2-9"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.2-10"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.3-0"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.3-1"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.3-2"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.3-3"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.3-4"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.3-5"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.3-6"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.3-7"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.3-8"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.3-9"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.3-10"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.4-0"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.4-1"
},
{
"introduced": "0"
},
{
"last_affected": "7.0.4-2"
}
]
}"2026-04-11T04:14:36Z"
[
{
"id": "CVE-2017-5508-8c565714",
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick/commit/c073a7712d82476b5fbee74856c46b88af9c3175",
"signature_version": "v1",
"signature_type": "Function",
"target": {
"function": "ReadTIFFImage",
"file": "coders/tiff.c"
},
"digest": {
"function_hash": "64327381050776383374483875130080754838",
"length": 23249.0
}
},
{
"id": "CVE-2017-5508-f2ebedec",
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick/commit/c073a7712d82476b5fbee74856c46b88af9c3175",
"signature_version": "v1",
"signature_type": "Line",
"target": {
"file": "coders/tiff.c"
},
"digest": {
"threshold": 0.9,
"line_hashes": [
"339783385470963704518081453680787509394",
"170187431441979370390447072169831908618",
"64693590836930932883851585134442121071",
"90088925699755770610197656072186626388",
"31699036766545690104974140604545672305"
]
}
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-5508.json"