Buffer overflow in GraphicsMagick - CVE-2017-14042
Published: August 31, 2017 / Updated: August 3, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
A memory allocation failure was discovered in the ReadPNMImage function in coders/pnm.c in GraphicsMagick 1.3.26. The vulnerability causes a big memory allocation, which may lead to remote denial of service in the MagickRealloc function in magick/memory.c.
Affected software
graphicsmagick (Alpine package)
GraphicsMagick
Fedora
SUSE Linux
Opensuse
How to mitigate CVE-2017-14042
graphicsmagick (Alpine package) - addressed in versions 1.3.26-r5, 1.3.27-r0
GraphicsMagick - addressed in versions 1.3.34-1.el7, 1.3.34-1.el8