Input validation error in GraphicsMagick - CVE-2017-13776

 

Input validation error in GraphicsMagick - CVE-2017-13776

Published: August 30, 2017 / Updated: August 4, 2020


Vulnerability identifier: #VU33772
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13776
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version!=10 case that results in the reader not returning; it would cause large amounts of CPU and memory consumption although the crafted file itself does not request it.


Affected software

GraphicsMagick
Arch Linux
Fedora
graphicsmagick (Alpine package)
GraphicsMagick

How to mitigate CVE-2017-13776

Install update from vendor's website.

GraphicsMagick - update to 1.3.27
graphicsmagick (Alpine package) - update to 1.3.25-r4
GraphicsMagick - addressed in versions 1.3.34-1.el7, 1.3.34-1.el8

External References

Related Security Bulletins