Input validation error in GraphicsMagick - CVE-2017-13775

 

Input validation error in GraphicsMagick - CVE-2017-13775

Published: August 30, 2017 / Updated: August 4, 2020


Vulnerability identifier: #VU33771
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13775
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

GraphicsMagick 1.3.26 has a denial of service issue in ReadJNXImage() in coders/jnx.c whereby large amounts of CPU and memory resources may be consumed although the file itself does not support the requests.


Affected software

GraphicsMagick
graphicsmagick (Alpine package)
GraphicsMagick
Fedora

How to mitigate CVE-2017-13775

Install update from vendor's website.

GraphicsMagick - update to 1.3.27
graphicsmagick (Alpine package) - update to 1.3.25-r4
GraphicsMagick - addressed in versions 1.3.32-1.fc29, 1.3.32-1.fc30, 1.3.34-1.el7, 1.3.34-1.el8

External References

Related Security Bulletins