PT-2019-4974 · Graphicsmagick+3 · Graphicsmagick+3

Galycannon

·

Published

2019-04-24

·

Updated

2024-06-15

·

CVE-2019-11506

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GraphicsMagick versions 1.3.30 through 1.4 snapshot-20190403 Q8
Description The issue is related to a heap-based buffer overflow in the WriteMATLABImage function, located in coders/mat.c, which can be triggered by a crafted image file. This may allow an attacker to cause a denial of service or have other unspecified impacts. The vulnerability is also related to ExportRedQuantumType in magick/export.c.
Recommendations For GraphicsMagick versions 1.3.30 through 1.4 snapshot-20190403 Q8, consider disabling the WriteMATLABImage function as a temporary workaround until a patch is available. Restrict the use of crafted image files to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2894
ALT-PU-2021-1452
BDU:2020-01594
CVE-2019-11506
DLA-1795-1
DSA-4640-1
MGASA-2019-0187
OPENSUSE-SU-2019:1354-1
OPENSUSE-SU-2019:1437-1
OPENSUSE-SU-2019:1603-1
OPENSUSE-SU-2019_1354-1
OPENSUSE-SU-2019_1355-1
OPENSUSE-SU-2019_1603-1
OPENSUSE-SU-2019_1683-1
OPENSUSE-SU-2024:11564-1
SUSE-SU-2019:1523-1
SUSE-SU-2019:1712-1
USN-4207-1

Affected Products

Alt Linux
Graphicsmagick
Suse
Ubuntu