[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2016-752 ---- GraphicsMagick

ID: oval:org.secpod.oval:def:1600462Date: (C)2016-10-18   (M)2021-06-02
Class: PATCHFamily: unix




A possible heap overflow was discovered in the EscapeParenthesis function .Various issues were found in the processing of SVG files in GraphicsMagick .The TIFF reader had a bug pertaining to use of TIFFGetField when a "count" value is returned. The bug caused a heap read overflow which could allow an untrusted file to crash the software .The Utah RLE reader did not validate that header information was reasonable given the file size and so it could cause huge memory allocations and/or consume huge amounts of CPU, causing a denial of service

Platform:
Amazon Linux AMI
Product:
GraphicsMagick
Reference:
ALAS-2016-752
CVE-2016-7447
CVE-2016-7446
CVE-2016-7449
CVE-2016-7448
CVE    4
CVE-2016-7448
CVE-2016-7449
CVE-2016-7446
CVE-2016-7447
...
CPE    2
cpe:/o:amazon:linux
cpe:/a:graphicsmagick:graphicsmagick

© SecPod Technologies