Description
In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bits/sample), and therefore lacks indexes initialization.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-1619-1 | graphicsmagick security update |
Debian DSA |
DSA-4640-1 | graphicsmagick security update |
EUVD |
EUVD-2018-12756 | In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bits/sample), and therefore lacks indexes initialization. |
Ubuntu USN |
USN-4207-1 | GraphicsMagick vulnerabilities |
Ubuntu USN |
USN-5974-1 | GraphicsMagick vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T11:58:18.393Z
Reserved: 2018-12-17T00:00:00.000Z
Link: CVE-2018-20189
No data.
Status : Modified
Published: 2018-12-17T20:29:00.247
Modified: 2024-11-21T04:01:03.240
Link: CVE-2018-20189
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN