CVE-2008-3134
published 2008-07-10CVE-2008-3134: Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory…
PriorityP420medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
2.13%
80.0th percentile
Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | graphicsmagick | < graphicsmagick 1.2.4-1 (bookworm) | graphicsmagick 1.2.4-1 (bookworm) |
| debian | imagemagick | < graphicsmagick 1.2.4-1 (bookworm) | graphicsmagick 1.2.4-1 (bookworm) |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | >= 0 < 1.2.4-1 | 1.2.4-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.2.4-1 | 1.2.4-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.2.4-1 | 1.2.4-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.2.4-1 | 1.2.4-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h39h-mv79-2m42: Multiple unspecified vulnerabilities in GraphicsMagick before 1
ghsa_unreviewed·2022-05-01
CVE-2008-3134 [MEDIUM] GHSA-h39h-mv79-2m42: Multiple unspecified vulnerabilities in GraphicsMagick before 1
Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.
OSV
CVE-2008-3134: Multiple unspecified vulnerabilities in GraphicsMagick before 1
osv·2008-07-10·CVSS 5.0
CVE-2008-3134 [MEDIUM] CVE-2008-3134: Multiple unspecified vulnerabilities in GraphicsMagick before 1
Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.
Red Hat
GraphicsMagick/ImageMagick: multiple crash or DoS issues
vendor_redhat·2008-06-11·CVSS 5.0
CVE-2008-3134 [MEDIUM] GraphicsMagick/ImageMagick: multiple crash or DoS issues
GraphicsMagick/ImageMagick: multiple crash or DoS issues
Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.
Statement: We do not consider a crash of a client application such as ImageMagick to be a
security issue.
Debian
CVE-2008-3134: graphicsmagick - Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote...
vendor_debian·2008·CVSS 5.0
CVE-2008-3134 [MEDIUM] CVE-2008-3134: graphicsmagick - Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote...
Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.
Scope: local
bookworm: resolved (fixed in 1.2.4-1)
bullseye: resolved (fixed in 1.2.4-1)
forky: resolved (fixed in 1.2.4-1)
sid: resolved (fixed in 1.2.4-1)
trixie: resolved (fixed in 1.2.4-1)
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00004.htmlhttp://secunia.com/advisories/30879http://secunia.com/advisories/32151http://sourceforge.net/forum/forum.php?forum_id=841176http://sourceforge.net/project/shownotes.php?release_id=610253http://www.securityfocus.com/bid/30055http://www.securitytracker.com/id?1020413http://www.vupen.com/english/advisories/2008/1984/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43511https://exchange.xforce.ibmcloud.com/vulnerabilities/43513http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00004.htmlhttp://secunia.com/advisories/30879http://secunia.com/advisories/32151http://sourceforge.net/forum/forum.php?forum_id=841176http://sourceforge.net/project/shownotes.php?release_id=610253http://www.securityfocus.com/bid/30055http://www.securitytracker.com/id?1020413http://www.vupen.com/english/advisories/2008/1984/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/43511https://exchange.xforce.ibmcloud.com/vulnerabilities/43513
2008-07-10
Published