CVE-2017-13145: Canonical Ubuntu Linux

Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.

In ImageMagick before 6.9.8-8 and 7.x before 7.0.5-9, the ReadJP2Image function in coders/jp2.c does not properly validate the channel geometry, leading to a crash.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
  • Debian Debian Linux: version 8.0 only; version 9.0 only
  • ImageMagick ImageMagick: up to and including 6.9.8-7; version 7.0.1-0 only; version 7.0.1-1 only; version 7.0.1-2 only; version 7.0.1-3 only; version 7.0.1-4 only; …

Published 2017-08-23. Last modified 2026-06-17.