CVE-2017-11140Uncontrolled Resource Consumption in Graphicsmagick

Severity
5.5MEDIUMNVD
EPSS
0.6%
top 31.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10
Latest updateMay 13

Description

The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a pixel cache before a successful read of a scanline, which allows remote attackers to cause a denial of service (resource consumption) via crafted JPEG files.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

debiandebian/graphicsmagick< graphicsmagick 1.3.26-3 (bookworm)
Debiangraphicsmagick/graphicsmagick< 1.3.26-3+3
Ubuntugraphicsmagick/graphicsmagick< 1.3.23-1ubuntu0.2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4922-82mh-7xp2: The ReadJPEGImage function in coders/jpeg2022-05-13
OSV
graphicsmagick vulnerabilities2019-12-02
OSV
CVE-2017-11140: The ReadJPEGImage function in coders/jpeg2017-07-10

📋Vendor Advisories

2
Ubuntu
GraphicsMagick vulnerabilities2019-12-02
Debian
CVE-2017-11140: graphicsmagick - The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a p...2017

💬Community

3
Bugzilla
CVE-2017-11140 GraphicsMagick: Resource exhaustion denial of service in ReadJPEGImage function [fedora-all]2017-07-21
Bugzilla
CVE-2017-11140 GraphicsMagick: Resource exhaustion denial of service in ReadJPEGImage function [epel-all]2017-07-21
Bugzilla
CVE-2017-11140 GraphicsMagick: Resource exhaustion denial of service in ReadJPEGImage function2017-07-21