PT-2019-5205 · Graphicsmagick+3 · Graphicsmagick+3

Galycannon

·

Published

2019-04-08

·

Updated

2021-03-09

·

CVE-2019-11005

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GraphicsMagick versions 1.4 snapshot-20190322 Q8 and earlier
Description The issue is related to a buffer overflow in the SVGStartElement function of the GraphicsMagick graphic editor, which can be exploited by a remote attacker to gain unauthorized access to information, compromise its integrity and availability, or cause a denial of service (application crash) via a quoted font family value in the coders/svg.c file.
Recommendations For GraphicsMagick version 1.4 snapshot-20190322 Q8 and earlier, consider disabling the SVGStartElement function as a temporary workaround until a patch is available. Restrict access to the coders/svg.c file to minimize the risk of exploitation. Avoid using quoted font family values in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Memory Corruption

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2894
ALT-PU-2021-1452
BDU:2020-01906
CVE-2019-11005
DSA-4640-1
MGASA-2019-0187
OPENSUSE-SU-2019:1272-1
OPENSUSE-SU-2019:1295-1
OPENSUSE-SU-2019_1272-1
USN-4207-1

Affected Products

Alt Linux
Graphicsmagick
Suse
Ubuntu