CVE-2017-16545: Graphicsmagick
High severity, CVSS 8.8. EPSS: 2.2% chance of exploitation in the next 30 days.
The ReadWPGImage function in coders/wpg.c in GraphicsMagick 1.3.26 does not properly validate colormapped images, which allows remote attackers to cause a denial of service (ImportIndexQuantumType invalid write and application crash) or possibly have unspecified other impact via a malformed WPG image.
Affected products
- Graphicsmagick Graphicsmagick: version 1.3.26 only
Published 2017-11-05. Last modified 2026-06-17.