Logo
componentgraphicsmagick
Name
graphicsmagick
Version
1.3.45-r
Type
library
Description
-
Licenses
-
PURL
-
CPE
cpe:2.3:a:graphicsmagick:graphicsmagick:1.3.45:*:*:*:*:*:*:*

Other Versions#


Project
Branch
Version
master
1.3.46-r1

Vulnerabilities#


Name
Analysis
Description
Exploitable
GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.
Exploitable
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.
Exploitable
ReadJXLImage in JXL in GraphicsMagick before 1.3.46 lacks image dimension resource limits.
Exploitable
Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors in DPX images. NOTE: some of these details are obtained from third party information.
Exploitable
Buffer overflow in GraphicsMagick and ImageMagick allows user-assisted remote attackers to cause a denial of service and possibly execute arbitrary code via a PALM image that is not properly handled by the ReadPALMImage function in coders/palm.c. NOTE: this issue is due to an incomplete patch for CVE-2006-5456.