coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in magick/pixel_cache.c.
References
Configurations
History
21 Nov 2024, 03:16
Type | Values Removed | Values Added |
---|---|---|
References | () http://hg.code.sf.net/p/graphicsmagick/code/rev/135bdcb88b8d - Patch | |
References | () http://hg.code.sf.net/p/graphicsmagick/code/rev/1b9e64a8901e - Patch | |
References | () http://hg.code.sf.net/p/graphicsmagick/code/rev/2a21cda3145b - Patch | |
References | () http://hg.code.sf.net/p/graphicsmagick/code/rev/2b7c826d36af - Patch | |
References | () http://hg.code.sf.net/p/graphicsmagick/code/rev/3dc7b4e3779d - Patch | |
References | () http://hg.code.sf.net/p/graphicsmagick/code/rev/75245a215fff - Patch | |
References | () http://hg.code.sf.net/p/graphicsmagick/code/rev/e8086faa52d0 - Patch | |
References | () http://hg.code.sf.net/p/graphicsmagick/code/rev/fcd3ed3394f6 - Patch | |
References | () http://www.securityfocus.com/bid/101795 - Third Party Advisory, VDB Entry | |
References | () https://lists.debian.org/debian-lts-announce/2017/11/msg00013.html - Mailing List, Third Party Advisory | |
References | () https://lists.debian.org/debian-lts-announce/2018/06/msg00009.html - Mailing List, Third Party Advisory | |
References | () https://sourceforge.net/p/graphicsmagick/bugs/450/ - Exploit, Issue Tracking, Patch, Third Party Advisory | |
References | () https://usn.ubuntu.com/4248-1/ - | |
References | () https://www.debian.org/security/2018/dsa-4321 - Third Party Advisory |
Information
Published : 2017-11-09 00:29
Updated : 2024-11-21 03:16
NVD link : CVE-2017-16669
Mitre link : CVE-2017-16669
CVE.ORG link : CVE-2017-16669
JSON object : View
Products Affected
debian
- debian_linux
graphicsmagick
- graphicsmagick
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer