PT-2018-1885 · Graphicsmagick+3 · Graphicsmagick+3

Trace Probe

·

Published

2018-03-25

·

Updated

2023-03-27

·

CVE-2018-9018

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GraphicsMagick version 1.3.28
Description The issue is related to a divide-by-zero error in the ReadMNGImage function of coders/png.c. This error can be triggered by remote attackers using a crafted mng file, potentially causing a crash and denial of service. The vulnerability allows an attacker to exploit this flaw and cause the application to crash using a specially crafted image.
Recommendations For GraphicsMagick version 1.3.28, as a temporary workaround, consider disabling the ReadMNGImage function until a patch is available. Restrict access to the coders/png.c module to minimize the risk of exploitation. Avoid using the ReadMNGImage function with untrusted mng files until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Divide By Zero

Weakness Enumeration

Related Identifiers

BDU:2018-01488
CVE-2018-9018
DLA-1322-1
DLA-1456-1
DSA-4321-1
DSA-4321-2
MGASA-2018-0285
SUSE-SU-2018:1036-1
SUSE-SU-2018:1129-1
SUSE-SU-2018:1178-1
USN-5974-1

Affected Products

Graphicsmagick
Linuxmint
Suse
Ubuntu