CVE-2020-12672Out-of-bounds Write in Graphicsmagick

CWE-787Out-of-bounds Write10 documents7 sources
Severity
7.5HIGHNVD
EPSS
2.7%
top 14.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6
Latest updateMar 27

Description

GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

Debiangraphicsmagick/graphicsmagick< 1.4+really1.3.35-2+3
NVDopensuse/leap15.1

Also affects: Debian Linux 8.0

🔴Vulnerability Details

3
GHSA
GHSA-cg2w-mf57-v7rg: GraphicsMagick through 12022-05-24
OSV
CVE-2020-12672: GraphicsMagick through 12020-05-06
CVEList
CVE-2020-12672: GraphicsMagick through 12020-05-06

📋Vendor Advisories

3
Ubuntu
GraphicsMagick vulnerabilities2023-03-27
Ubuntu
GraphicsMagick vulnerabilities2022-08-30
Debian
CVE-2020-12672: graphicsmagick - GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage i...2020

💬Community

3
Bugzilla
CVE-2020-12672 GraphicsMagick: a heap-based buffer overflow in ReadMNGImage in coders/png.c [epel-all]2020-05-21
Bugzilla
CVE-2020-12672 GraphicsMagick: a heap-based buffer overflow in ReadMNGImage in coders/png.c [fedora-all]2020-05-21
Bugzilla
CVE-2020-12672 graphicsmagick: a heap-based buffer overflow in ReadMNGImage in coders/png.c2020-05-21
CVE-2020-12672 — Out-of-bounds Write in Graphicsmagick | cvebase