CVE-2017-10800Uncontrolled Resource Consumption in Graphicsmagick

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 44.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 3
Latest updateMay 14

Description

When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMATImage() if the size specified for a MAT Object is larger than the actual amount of data.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/graphicsmagick< graphicsmagick 1.3.26-1 (bookworm)
Debiangraphicsmagick/graphicsmagick< 1.3.26-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-ccwp-q88v-h469: When GraphicsMagick 12022-05-14
OSV
CVE-2017-10800: When GraphicsMagick 12017-07-03

📋Vendor Advisories

1
Debian
CVE-2017-10800: graphicsmagick - When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead...2017

💬Community

3
Bugzilla
CVE-2017-10800 GraphicsMagick: CVE-2017-10800 [fedora-all]2017-07-03
Bugzilla
CVE-2017-10800 GraphicsMagick: out of memory in ReadMATImage() function2017-07-03
Bugzilla
CVE-2017-10800 GraphicsMagick: out of memory in ReadMATImage() function [epel-all]2017-07-03