CVE-2017-18229Allocation of Resources Without Limits or Throttling in Graphicsmagick

Severity
6.5MEDIUMNVD
EPSS
1.3%
top 20.45%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 14
Latest updateMay 13

Description

An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via a crafted file, because file size is not properly used to restrict scanline, strip, and tile allocations.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/graphicsmagick< graphicsmagick 1.3.27-1 (bookworm)
Debiangraphicsmagick/graphicsmagick< 1.3.27-1+3

Also affects: Debian Linux 7.0, 8.0, 9.0

🔴Vulnerability Details

2
GHSA
GHSA-gmqc-66m4-mcgh: An issue was discovered in GraphicsMagick 12022-05-13
OSV
CVE-2017-18229: An issue was discovered in GraphicsMagick 12018-03-14

📋Vendor Advisories

3
Ubuntu
GraphicsMagick vulnerabilities2020-02-04
Red Hat
GraphicsMagick: allocation failure in ReadTIFFImage function in coders/tiff.c2017-09-13
Debian
CVE-2017-18229: graphicsmagick - An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerab...2017

💬Community

1
Bugzilla
CVE-2017-18229 GraphicsMagick: allocation failure in ReadTIFFImage function in coders/tiff.c2018-03-20