Input validation error in GraphicsMagick - CVE-2017-13777

 

Input validation error in GraphicsMagick - CVE-2017-13777

Published: August 30, 2017 / Updated: August 4, 2020


Vulnerability identifier: #VU33782
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-13777
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.

GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version==10 case that results in the reader not returning; it would cause large amounts of CPU and memory consumption although the crafted file itself does not request it.


Affected software

GraphicsMagick
Arch Linux
Fedora
graphicsmagick (Alpine package)
GraphicsMagick

How to mitigate CVE-2017-13777

Install update from vendor's website.

GraphicsMagick - update to 1.3.27
graphicsmagick (Alpine package) - update to 1.3.25-r4
GraphicsMagick - addressed in versions 1.3.34-1.el7, 1.3.34-1.el8

External References

Related Security Bulletins