CVE-2019-11473Out-of-bounds Read in Graphicsmagick

CWE-125Out-of-bounds Read9 documents7 sources
Severity
6.5MEDIUMNVD
CNA8.8OSV8.8
EPSS
1.3%
top 20.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 23
Latest updateMay 24

Description

coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (out-of-bounds read and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

Patches

🔴Vulnerability Details

3
GHSA
GHSA-ccw4-q694-p6gw: coders/xwd2022-05-24
OSV
CVE-2019-11473: coders/xwd2019-04-23
CVEList
CVE-2019-11473: coders/xwd2019-04-23

📋Vendor Advisories

2
Ubuntu
GraphicsMagick vulnerabilities2019-12-03
Debian
CVE-2019-11473: graphicsmagick - coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of serv...2019

💬Community

3
Bugzilla
CVE-2019-11473 graphicsmagick: out of bounds in coders/xwd.c causing denial of service by crafting an XWD image file2019-05-08
Bugzilla
CVE-2019-11473 GraphicsMagick: out of bounds in coders/xwd.c causing denial of service by crafting an XWD image file [epel-all]2019-05-08
Bugzilla
CVE-2019-11473 GraphicsMagick: out of bounds in coders/xwd.c causing denial of service by crafting an XWD image file [fedora-all]2019-05-08