CVE-2013-4589
published 2013-11-23CVE-2013-4589: The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors…
PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
2.33%
81.6th percentile
The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.
Affected
49 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | graphicsmagick | < graphicsmagick 1.3.18-1 (bookworm) | graphicsmagick 1.3.18-1 (bookworm) |
| fedoraproject | fedora | — | — |
| graphicsmagick | graphicsmagick | <= 1.3.17 | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vj5h-42mr-vg2g: The ExportAlphaQuantumType function in export
ghsa_unreviewed·2022-05-17
CVE-2013-4589 [MEDIUM] GHSA-vj5h-42mr-vg2g: The ExportAlphaQuantumType function in export
The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.
OSV
CVE-2013-4589: The ExportAlphaQuantumType function in export
osv·2013-11-23·CVSS 4.3
CVE-2013-4589 [MEDIUM] CVE-2013-4589: The ExportAlphaQuantumType function in export
The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.
Debian
CVE-2013-4589: graphicsmagick - The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 ...
vendor_debian·2013·CVSS 4.3
CVE-2013-4589 [MEDIUM] CVE-2013-4589: graphicsmagick - The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 ...
The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.
Scope: local
bookworm: resolved (fixed in 1.3.18-1)
bullseye: resolved (fixed in 1.3.18-1)
forky: resolved (fixed in 1.3.18-1)
sid: resolved (fixed in 1.3.18-1)
trixie: resolved (fixed in 1.3.18-1)
No detection rules found.
No public exploits indexed.
http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00032.htmlhttp://secunia.com/advisories/55288http://secunia.com/advisories/55721http://security.gentoo.org/glsa/glsa-201311-10.xmlhttp://sourceforge.net/p/graphicsmagick/code/ci/1a2d7a38363f7f23b63d626887d22d39c7240144/http://sourceforge.net/p/graphicsmagick/discussion/250737/thread/20888e8b/http://www.openwall.com/lists/oss-security/2013/11/15/14http://www.securityfocus.com/bid/63002https://bugzilla.redhat.com/show_bug.cgi?id=1019085http://lists.fedoraproject.org/pipermail/package-announce/2013-November/120008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-06/msg00032.htmlhttp://secunia.com/advisories/55288http://secunia.com/advisories/55721http://security.gentoo.org/glsa/glsa-201311-10.xmlhttp://sourceforge.net/p/graphicsmagick/code/ci/1a2d7a38363f7f23b63d626887d22d39c7240144/http://sourceforge.net/p/graphicsmagick/discussion/250737/thread/20888e8b/http://www.openwall.com/lists/oss-security/2013/11/15/14http://www.securityfocus.com/bid/63002https://bugzilla.redhat.com/show_bug.cgi?id=1019085
2013-11-23
Published