PT-2013-5084 · Graphicsmagick+1 · Graphicsmagick+1

Published

2013-11-22

·

Updated

2023-09-12

·

CVE-2013-4589

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions GraphicsMagick versions prior to 1.3.18
Description The issue is related to the ExportAlphaQuantumType function in export.c, which might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.
Recommendations For versions prior to 1.3.18, update to version 1.3.18 or later to resolve the issue. As a temporary workaround, consider restricting the use of the ExportAlphaQuantumType function when exporting the alpha of an 8-bit RGBA image until a patch is available.

Exploit

Fix

Related Identifiers

CVE-2013-4589
MGASA-2013-0350
MGASA-2013-0355
SUSE-SU-2016:1614-1
SUSE-SU-2016_1614-1

Affected Products

Graphicsmagick
Suse