CVE-2017-13777
CVE-2017-13777 is a medium-severity vulnerability in Graphicsmagick with a CVSS 3.x base score of 6.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-834.
Key facts
- Severity: Medium (CVSS 3.x base score 6.5)
- CVSS v2: 7.1
- EPSS exploit prediction: 2% (81st percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-834
- Affected product: Graphicsmagick
- Published:
- Last modified:
Description
GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version==10 case that results in the reader not returning; it would cause large amounts of CPU and memory consumption although the crafted file itself does not request it.
Frequently asked questions
- What is CVE-2017-13777?
- GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version==10 case that results in the reader not returning; it would cause large amounts of CPU and memory consumption although the crafted file itself does not request it.
- How severe is CVE-2017-13777?
- CVE-2017-13777 has a CVSS 3.x base score of 6.5, rated medium severity. It is exploitable over network with low attack complexity, requires no privileges and user interaction. Impact on confidentiality is none, integrity none, and availability high.
- Is CVE-2017-13777 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 2% (81st percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2017-13777?
- CVE-2017-13777 primarily affects Graphicsmagick. In total, 3 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
- How do I fix CVE-2017-13777?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2017-13777 published?
- CVE-2017-13777 was published on 2017-08-30 and last updated on 2026-06-17.
References
- http://hg.code.sf.net/p/graphicsmagick/code/rev/233a720bfd5e
- http://openwall.com/lists/oss-security/2017/08/31/1
- http://www.securityfocus.com/bid/100575
- https://lists.debian.org/debian-lts-announce/2018/08/msg00002.html
- https://usn.ubuntu.com/4222-1/
- https://www.debian.org/security/2018/dsa-4321
Affected products (3)
- cpe:2.3:a:graphicsmagick:graphicsmagick:1.3.26:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
- cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
More vulnerabilities in Graphicsmagick
- CVE-2008-6071 — Critical (CVSS 10.0): Heap-based buffer overflow in the DecodeImage function in coders/pict.c in GraphicsMagick before 1.1.14, and 1.2.x…
- CVE-2020-10938 — Critical (CVSS 9.8): GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in…
- CVE-2019-19951 — Critical (CVSS 9.8): In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of…
- CVE-2019-19950 — Critical (CVSS 9.8): In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of…
- CVE-2019-11005 — Critical (CVSS 9.8): In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of…
- CVE-2017-11643 — Critical (CVSS 9.8): GraphicsMagick 1.3.26 has a heap overflow in the WriteCMYKImage() function in coders/cmyk.c when processing multiple…
All CVEs affecting Graphicsmagick →
Other CWE-834 (Excessive Iteration) vulnerabilities
- CVE-2017-12587 — High (CVSS 8.8): ImageMagick 7.0.6-1 has a large loop vulnerability in the ReadPWPImage function in coders\pwp.c.
- CVE-2026-59644 — High (CVSS 8.7): In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.
- CVE-2024-42071 — High (CVSS 7.8): In the Linux kernel, the following vulnerability has been resolved: ionic: use dev_consume_skb_any outside of napi If…
- CVE-2026-64641 — High (CVSS 7.5): Next.js is a React framework for building full-stack web applications. In versions 13.0.0 through 15.5.20 and 16.0.0…
- CVE-2025-62707 — High (CVSS 7.5): pypdf is a free and open-source pure-python PDF library. Prior to version 6.1.3, an attacker who uses this…
- CVE-2025-56571 — High (CVSS 7.5): Finance.js v4.1.0 contains a Denial of Service (DoS) vulnerability via the IRR function’s depth parameter. Improper…