#VU18364 Out-of-bounds read in GraphicsMagick - CVE-2019-11006
Published: April 28, 2019 / Updated: June 17, 2019
GraphicsMagick
GraphicsMagick Group
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c in MIFF reader, which allows attackers to cause a denial of service or information disclosure via an RLE packet. A remote attacker can perform a denial of service attack.
Remediation
External links
- http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/f7610c1281c1
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00093.html
- https://lists.debian.org/debian-lts-announce/2019/04/msg00015.html
- https://sourceforge.net/p/graphicsmagick/bugs/598/
- http://www.graphicsmagick.org/NEWS.html#june-15-2019