CVE-2017-16547: Graphicsmagick
High severity, CVSS 8.8. EPSS: 2.3% chance of exploitation in the next 30 days.
The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of service (negative strncpy and application crash) or possibly have unspecified other impact via a crafted file.
Affected products
- Graphicsmagick Graphicsmagick: version 1.3.26 only
Published 2017-11-06. Last modified 2026-06-17.