8.1
CVSSv3

CVE-2019-11009

Published: 08/04/2019 Updated: 23/05/2019
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Vulnerability Summary

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadXWDImage of coders/xwd.c, which allows malicious users to cause a denial of service or information disclosure via a crafted image file.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

graphicsmagick graphicsmagick

opensuse leap 42.3

opensuse leap 15.0

debian debian linux 8.0

Vendor Advisories

Debian Bug report logs - #927029 graphicsmagick: Multiple heap-based buffer over-reads Package: graphicsmagick; Maintainer for graphicsmagick is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Source for graphicsmagick is src:graphicsmagick (PTS, buildd, popcon) Reported by: Markus Koschany <apo@debianorg> Date: Sat, 13 ...
Several security issues were fixed in GraphicsMagick ...
This update fixes several vulnerabilities in Graphicsmagick: Various memory handling problems and cases of missing or incomplete input sanitising may result in denial of service, memory disclosure or the execution of arbitrary code if malformed media files are processed For the oldstable distribution (stretch), these problems have been fixed in ve ...