CVE-2017-11352: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 1.8% chance of exploitation in the next 30 days.

In ImageMagick before 7.0.5-10, a crafted RLE image can trigger a crash because of incorrect EOF handling in coders/rle.c. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-9144.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only
  • ImageMagick ImageMagick: before 6.9.8-9 (fixed in 6.9.8-9); from 7.0.0-0, before 7.0.5-10 (fixed in 7.0.5-10)

Published 2017-07-17. Last modified 2026-06-17.