In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads heap data beyond the allocated region.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade GraphicsMagick | Mar 9, 2018 | Dec 27, 2017 |
| Debian | — | Upgrade graphicsmagick | Oct 18, 2018 | Dec 27, 2017 |
| Suse | — | Upgrade libGraphicsMagick2Upgrade graphicsmagickUpgrade perl-graphicsmagick | Feb 17, 2018 | Dec 27, 2017 |
| Ubuntu | — | Upgrade libgraphicsmagick-q16-3Upgrade graphicsmagickUpgrade libgraphicsmagick++-q16-12 | Feb 6, 2020 | Dec 27, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub