CVE-2017-18272: ImageMagick

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

In ImageMagick 7.0.7-16 Q16 x86_64 2017-12-25, there is a use-after-free in ReadOneMNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted MNG image file that is mishandled in an MngInfoDiscardObject call.

Affected products

  • ImageMagick ImageMagick: from 7.0.7-16, before 7.0.7-21 (fixed in 7.0.7-21)

Published 2018-05-18. Last modified 2026-06-17.