#VU18365 Out-of-bounds read in GraphicsMagick - CVE-2019-11007
Published: April 28, 2019
GraphicsMagick
GraphicsMagick Group
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap. A remote attacker can perform a denial of service attack.
Remediation
External links
- http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/40fc71472b98
- http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/86a9295e7c83
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00093.html
- https://lists.debian.org/debian-lts-announce/2019/04/msg00015.html
- https://sourceforge.net/p/graphicsmagick/bugs/596/