6.5
CVSSv3

CVE-2018-20184

Published: 17/12/2018 Updated: 24/08/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows malicious users to cause a denial of service via a crafted image file, because the number of rows or columns can exceed the pixel-dimension restrictions of the TGA specification.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

graphicsmagick graphicsmagick 1.4

debian debian linux 8.0

Vendor Advisories

Several security issues were fixed in GraphicsMagick ...
This update fixes several vulnerabilities in Graphicsmagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed media files are processed For the oldstable distribution (stretch), these problems have been fixed in ve ...
Debian Bug report logs - #916719 graphicsmagick: CVE-2018-20185 Package: src:graphicsmagick; Maintainer for src:graphicsmagick is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 17 Dec 2018 20:39:01 UTC Severity: important Tags: fixed-upstream, patch, securi ...
Debian Bug report logs - #916752 graphicsmagick: CVE-2018-20189 Package: src:graphicsmagick; Maintainer for src:graphicsmagick is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Tue, 18 Dec 2018 09:18:04 UTC Severity: important Tags: patch, security, upstream Fo ...
Debian Bug report logs - #916721 graphicsmagick: CVE-2018-20184 Package: src:graphicsmagick; Maintainer for src:graphicsmagick is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Mon, 17 Dec 2018 20:39:06 UTC Severity: important Tags: patch, security, upstream Fo ...