GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version!=10 case that results in the reader not returning; it would cause large amounts of CPU and memory consumption although the crafted file itself does not request it.
CVSS Details
- CVSS 3.0 Base Score: 6.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade graphicsmagick | Sep 20, 2017 | Aug 30, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Aug 30, 2017 |
| Debian | — | Upgrade graphicsmagick | Oct 18, 2018 | Aug 30, 2017 |
| Suse | — | Upgrade perl-GraphicsMagickUpgrade GraphicsMagickUpgrade libGraphicsMagick2 | Nov 15, 2017 | Aug 30, 2017 |
| Ubuntu | — | Upgrade libgraphicsmagick-q16-3Upgrade graphicsmagickUpgrade libgraphicsmagick++-q16-12 | Dec 17, 2019 | Aug 30, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub