In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing whether a limit has been reached.
CVSS Details
- CVSS 3.0 Base Score: 8.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux | — | Upgrade GraphicsMagick | Mar 9, 2018 | Dec 27, 2017 |
| Debian | — | Upgrade graphicsmagick | Oct 18, 2018 | Dec 27, 2017 |
| Suse | — | Upgrade libGraphicsMagick2Upgrade GraphicsMagickUpgrade perl-GraphicsMagick | Feb 14, 2018 | Dec 27, 2017 |
| Ubuntu | — | Upgrade libgraphicsmagick-q16-3Upgrade libgraphicsmagick++-q16-12Upgrade graphicsmagick | Feb 6, 2020 | Dec 27, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub