PT-2019-5205 · Graphicsmagick+3 · Graphicsmagick+3
Galycannon
·
Published
2019-04-08
·
Updated
2021-03-09
·
CVE-2019-11005
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
GraphicsMagick versions 1.4 snapshot-20190322 Q8 and earlier
Description
The issue is related to a buffer overflow in the
SVGStartElement function of the GraphicsMagick graphic editor, which can be exploited by a remote attacker to gain unauthorized access to information, compromise its integrity and availability, or cause a denial of service (application crash) via a quoted font family value in the coders/svg.c file.Recommendations
For GraphicsMagick version 1.4 snapshot-20190322 Q8 and earlier, consider disabling the
SVGStartElement function as a temporary workaround until a patch is available. Restrict access to the coders/svg.c file to minimize the risk of exploitation. Avoid using quoted font family values in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
DoS
Memory Corruption
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Graphicsmagick
Suse
Ubuntu