Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 598
Alerts This Week
Warning Icon 1 598

Debian 7 DLA-1082-1 Critical: Graphicsmagick Denial Of Service Issues

debian lts
Calendar Grey August 31, 2017
Scroller Debian Lts
Significant GraphicsMagick security flaws addressed in Debian 7, affecting ReadXBMImage(). Immediate upgrade advised for protection.
CVE-2017-13776 CVE-2017-13777 denial of service issue in ReadXBMImage()

Summary

CVE-2017-13776
CVE-2017-13777
denial of service issue in ReadXBMImage()

CVE-2017-12935
The ReadMNGImage function in coders/png.c mishandles large MNG
images, leading to an invalid memory read in the
SetImageColorCallBack function in magick/image.c.

CVE-2017-12936
The ReadWMFImage function in coders/wmf.c has a use-after-free
issue for data associated with exception reporting.

CVE-2017-12937
The ReadSUNImage function in coders/sun.c has a colormap
heap-based buffer over-read.

CVE-2017-13063
CVE-2017-13064
heap-based buffer overflow vulnerability in the function
GetStyleTokens in coders/svg.c

CVE-2017-13065
NULL pointer dereference vulnerability in the function
SVGStartElement in coders/svg.c


For Debian 7 "Wheezy", these problems have been fixed in version
1.3.16-1.1+deb7u9.

We recommend that you upgrade your graphicsmagick packages.

Further information about Debian LTS security advisories, how to apply

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: graphicsmagick
Version: 1.3.16-1.1+deb7u9
CVE ID: CVE-2017-12935 CVE-2017-12936 CVE-2017-12937 CVE-2017-13063

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.