Input validation error in GraphicsMagick - CVE-2017-13775
Published: August 30, 2017 / Updated: August 4, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
GraphicsMagick 1.3.26 has a denial of service issue in ReadJNXImage() in coders/jnx.c whereby large amounts of CPU and memory resources may be consumed although the file itself does not support the requests.
Affected software
graphicsmagick (Alpine package)
GraphicsMagick
Fedora
How to mitigate CVE-2017-13775
graphicsmagick (Alpine package) - update to 1.3.25-r4
GraphicsMagick - addressed in versions 1.3.32-1.fc29, 1.3.32-1.fc30, 1.3.34-1.el7, 1.3.34-1.el8
External References
- http://hg.code.sf.net/p/graphicsmagick/code/rev/b037d79b6ccd
- http://openwall.com/lists/oss-security/2017/08/31/3
- http://www.securityfocus.com/bid/100570
- https://lists.debian.org/debian-lts-announce/2018/08/msg00002.html
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PF62B5PJA2JDUOCKJGUQO3SPL74BEYSV/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/WHIKB4TP6KBJWT2UIPWL5MWMG5QXKGEJ/
- https://usn.ubuntu.com/4222-1/
- https://www.debian.org/security/2018/dsa-4321