CVE-2017-18230
published 2018-03-14CVE-2017-18230: An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which…
PriorityP424medium6.5CVSS 3.0
AVNACLPRNUIRSUCNINAH
EPSS
1.71%
75.0th percentile
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | graphicsmagick | < graphicsmagick 1.3.27-1 (bookworm) | graphicsmagick 1.3.27-1 (bookworm) |
| graphicsmagick | graphicsmagick | — | — |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.27-1 | 1.3.27-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.27-1 | 1.3.27-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.27-1 | 1.3.27-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.27-1 | 1.3.27-1 |
CVSS provenance
nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-55vr-xgpv-57cg: An issue was discovered in GraphicsMagick 1
ghsa_unreviewed·2022-05-13
CVE-2017-18230 [MEDIUM] CWE-476 GHSA-55vr-xgpv-57cg: An issue was discovered in GraphicsMagick 1
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file.
OSV
CVE-2017-18230: An issue was discovered in GraphicsMagick 1
osv·2018-03-14·CVSS 6.5
CVE-2017-18230 [MEDIUM] CVE-2017-18230: An issue was discovered in GraphicsMagick 1
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file.
Ubuntu
GraphicsMagick vulnerabilities
vendor_ubuntu·2020-02-04
CVE-2017-17912 GraphicsMagick vulnerabilities
Title: GraphicsMagick vulnerabilities
Summary: Several security issues were fixed in GraphicsMagick.
It was discovered that GraphicsMagick incorrectly handled certain image files.
An attacker could possibly use this issue to cause a denial of service or other
unspecified impact.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
GraphicsMagick: NULL pointer dereference in ReadCINEONImage function in coders/cineon.c
vendor_redhat·2017-09-25·CVSS 6.5
CVE-2017-18230 [MEDIUM] CWE-476 GraphicsMagick: NULL pointer dereference in ReadCINEONImage function in coders/cineon.c
GraphicsMagick: NULL pointer dereference in ReadCINEONImage function in coders/cineon.c
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file.
Package: GraphicsMagick (Red Hat Enterprise Linux 8) - Will not fix
Debian
CVE-2017-18230: graphicsmagick - An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vul...
vendor_debian·2017·CVSS 6.5
CVE-2017-18230 [MEDIUM] CVE-2017-18230: graphicsmagick - An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vul...
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.3.27-1)
bullseye: resolved (fixed in 1.3.27-1)
forky: resolved (fixed in 1.3.27-1)
sid: resolved (fixed in 1.3.27-1)
trixie: resolved (fixed in 1.3.27-1)
No detection rules found.
No public exploits indexed.
http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/53a4d841e90fhttps://lists.debian.org/debian-lts-announce/2018/03/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2018/08/msg00002.htmlhttps://sourceforge.net/p/graphicsmagick/bugs/473/https://usn.ubuntu.com/4266-1/https://www.debian.org/security/2018/dsa-4321http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/53a4d841e90fhttps://lists.debian.org/debian-lts-announce/2018/03/msg00025.htmlhttps://lists.debian.org/debian-lts-announce/2018/08/msg00002.htmlhttps://sourceforge.net/p/graphicsmagick/bugs/473/https://usn.ubuntu.com/4266-1/https://www.debian.org/security/2018/dsa-4321
2018-03-14
Published