CVE-2017-17499: Canonical Ubuntu Linux

Critical severity, CVSS 9.8. EPSS: 3.3% chance of exploitation in the next 30 days.

ImageMagick before 6.9.9-24 and 7.x before 7.0.7-12 has a use-after-free in Magick::Image::read in Magick++/lib/Image.cpp.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 17.10 only; version 18.04 only
  • Debian Debian Linux: version 9.0 only
  • ImageMagick ImageMagick: from 7.0.0-0, before 7.0.7-12 (fixed in 7.0.7-12); before 6.9.9-24 (fixed in 6.9.9-24)

Published 2017-12-11. Last modified 2026-06-17.