CVE-2017-16547: Graphicsmagick

High severity, CVSS 8.8. EPSS: 2.3% chance of exploitation in the next 30 days.

The DrawImage function in magick/render.c in GraphicsMagick 1.3.26 does not properly look for pop keywords that are associated with push keywords, which allows remote attackers to cause a denial of service (negative strncpy and application crash) or possibly have unspecified other impact via a crafted file.

Affected products

Published 2017-11-06. Last modified 2026-06-17.