PT-2017-3866 · Graphicsmagick+2 · Graphicsmagick+2
Hackyzh
·
Published
2017-10-22
·
Updated
2020-01-08
·
CVE-2017-15930
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GraphicsMagick version 1.3.26
Description
The issue is related to a Null Pointer Dereference in the
ReadOneJNGImage function, located in coders/png.c, which can occur while transferring JPEG scanlines. This is connected to a PixelPacket pointer. Exploitation of this issue may allow a remote attacker to execute arbitrary code.Recommendations
For GraphicsMagick version 1.3.26, consider disabling the
ReadOneJNGImage function as a temporary workaround until a patch is available. Restrict access to the coders/png.c module to minimize the risk of exploitation. Avoid using the PixelPacket pointer in the affected function until the issue is resolved.Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Graphicsmagick
Suse
Ubuntu