[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2017-820 ---- GraphicsMagick

ID: oval:org.secpod.oval:def:1600692Date: (C)2017-04-21   (M)2023-08-07
Class: PATCHFamily: unix




The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service via a small samples per pixel value in a CMYKA TIFF file.The WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service via vectors related to a ReferenceBlob and a NULL pointer.Heap-based buffer overflow in the WPG format reader in GraphicsMagick 1.3.25 and earlier allows remote attackers to have unspecified impact via a colormap with a large number of entries. The MagickMalloc function in magick/memory.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure and a "file truncation error for corrupt file." The ReadSCTImage function in coders/sct.c in GraphicsMagick 1.3.25 allows remote attackers to cause a denial of service via a crafted SCT header. The ReadPCXImage function in coders/pcx.c in GraphicsMagick 1.3.25 allows remote attackers to have unspecified impact via a crafted image, which triggers a memory allocation failure and a "file truncation error for corrupt file." The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a denial of service via large dimensions in a jpeg image. Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service via a crafted 8BIM chunk, which triggers a heap-based buffer overflow

Platform:
Amazon Linux AMI
Product:
GraphicsMagick
Reference:
ALAS-2017-820
CVE-2017-6335
CVE-2016-7997
CVE-2016-7996
CVE-2016-8684
CVE-2016-8682
CVE-2016-8683
CVE-2016-9830
CVE-2016-7800
CVE    8
CVE-2016-7800
CVE-2016-7996
CVE-2016-7997
CVE-2016-8682
...
CPE    3
cpe:/o:amazon:linux
cpe:/a:graphicsmagick:graphicsmagick
cpe:/a:graphicsmagick:graphicsmagick:1.3.25

© SecPod Technologies