cbcvebase.

Debian Graphicsmagick vulnerabilities

141 known vulnerabilities affecting debian/graphicsmagick.

Total CVEs
141
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL17HIGH47MEDIUM56LOW21

Vulnerabilities

Page 2 of 8
CVE-2019-19951P3CRITICALCVSS 9.8fixed in graphicsmagick 1.4~hg16039-1 (bookworm)2019
CVE-2019-19951 [CRITICAL] CVE-2019-19951: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflo... In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c. Scope: local bookworm: resolved (fixed in 1.4~hg16039-1) bullseye: resolved (fixed in 1.4~hg16039-1) forky: resolved (fixed in 1.4~hg16039-1) sid: resolved (fixed in 1.4~hg16039-1) trixie: resolved (fixed in 1.4~hg16039-1)
debian
CVE-2008-6071P3CRITICALCVSS 10.0fixed in graphicsmagick 1.2.3-1 (bookworm)2008
CVE-2008-6071 [CRITICAL] CVE-2008-6071: graphicsmagick - Heap-based buffer overflow in the DecodeImage function in coders/pict.c in Graph... Heap-based buffer overflow in the DecodeImage function in coders/pict.c in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PICT image. NOTE: some of these details are obtained from third party information. Scope: local bookworm: resolved (fixe
debian
CVE-2019-11505P3HIGHCVSS 8.8fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11505 [HIGH] CVE-2019-11505: graphicsmagick - In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a hea... In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in magick/bit_stream.c. Scope: local bookworm
debian
CVE-2019-12921P3MEDIUMCVSS 6.5fixed in graphicsmagick 1.4~hg16039-1 (bookworm)2019
CVE-2019-12921 [MEDIUM] CVE-2019-12921: graphicsmagick - In GraphicsMagick before 1.3.32, the text filename component allows remote attac... In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG. Scope: local bookworm: resolved (fixed in 1.4~hg16039-1) bullseye: resolved (fixed in 1.4~hg16039-1) forky: resolved (fixed in 1.4~hg16039-1) sid: resolved (fixed in 1.4~hg16039-1) trixie: resol
debian
CVE-2017-15277P3MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.26-14 (bookworm)2017
CVE-2017-15277 [MEDIUM] CVE-2017-15277: graphicsmagick - ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 le... ReadGIFImage in coders/gif.c in ImageMagick 7.0.6-1 and GraphicsMagick 1.3.26 leaves the palette uninitialized when processing a GIF file that has neither a global nor local palette. If the affected product is used as a library loaded into a process that operates on interesting data, this data sometimes can be leaked via the uninitialized palette. Scope: lo
debian
CVE-2019-11005P3CRITICALCVSS 9.8fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11005 [CRITICAL] CVE-2019-11005: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overfl... In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a quoted font family value. Scope: local bookworm: resolved (fixed in 1.4~hg15968-1) bullseye: resol
debian
CVE-2017-11643P3CRITICALCVSS 9.8fixed in graphicsmagick 1.3.26-4 (bookworm)2017
CVE-2017-11643 [CRITICAL] CVE-2017-11643: graphicsmagick - GraphicsMagick 1.3.26 has a heap overflow in the WriteCMYKImage() function in co... GraphicsMagick 1.3.26 has a heap overflow in the WriteCMYKImage() function in coders/cmyk.c when processing multiple frames that have non-identical widths. Scope: local bookworm: resolved (fixed in 1.3.26-4) bullseye: resolved (fixed in 1.3.26-4) forky: resolved (fixed in 1.3.26-4) sid: resolved (fixed in 1.3.26-4) trixie: resolved (fixed in 1.3.26-4)
debian
CVE-2019-11506P3HIGHCVSS 8.8fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11506 [HIGH] CVE-2019-11506: graphicsmagick - In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a he... In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in magick/export.c. Scope: local bookworm: r
debian
CVE-2009-1882P3MEDIUMCVSS 9.3fixed in graphicsmagick 1.3.5-5.1 (bookworm)2009
CVE-2009-1882 [CRITICAL] CVE-2009-1882: graphicsmagick - Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6... Integer overflow in the XMakeImage function in magick/xwindow.c in ImageMagick 6.5.2-8, and GraphicsMagick, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF file, which triggers a buffer overflow. NOTE: some of these details are obtained from third party information. Scope: local bookworm: r
debian
CVE-2005-4601P3HIGHCVSS 7.5fixed in graphicsmagick 1.1.7-1 (bookworm)2005
CVE-2005-4601 [HIGH] CVE-2005-4601: graphicsmagick - The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute ... The delegate code in ImageMagick 6.2.4.5-0.3 allows remote attackers to execute arbitrary commands via shell metacharacters in a filename that is processed by the display command. Scope: local bookworm: resolved (fixed in 1.1.7-1) bullseye: resolved (fixed in 1.1.7-1) forky: resolved (fixed in 1.1.7-1) sid: resolved (fixed in 1.1.7-1) trixie: resolved (fixed in
debian
CVE-2017-9098P3HIGHCVSS 7.5fixed in graphicsmagick 1.3.24-1 (bookworm)2017
CVE-2017-9098 [HIGH] CVE-2017-9098: graphicsmagick - ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized me... ImageMagick before 7.0.5-2 and GraphicsMagick before 1.3.24 use uninitialized memory in the RLE decoder, allowing an attacker to leak sensitive information from process memory space, as demonstrated by remote attacks against ImageMagick code in a long-running server process that converts image data on behalf of multiple users. This is caused by a missing initia
debian
CVE-2019-11008P3HIGHCVSS 8.8fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11008 [HIGH] CVE-2019-11008: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflo... In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer overflow in the function WriteXWDImage of coders/xwd.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file. Scope: local bookworm: resolved (fixed in 1.4~hg15968-1) bullseye: resolved (fixed in
debian
CVE-2019-19950P3CRITICALCVSS 9.8fixed in graphicsmagick 1.4~hg16039-1 (bookworm)2019
CVE-2019-19950 [CRITICAL] CVE-2019-19950: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowEx... In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c. Scope: local bookworm: resolved (fixed in 1.4~hg16039-1) bullseye: resolved (fixed in 1.4~hg16039-1) forky: resolved (fixed in 1.4~hg16039-1) sid: resolved (fixed in 1.4~hg16039-1) trixie: resolved (fixed in 1.4~hg16039-1)
debian
CVE-2017-11139P3LOWCVSS 9.8fixed in graphicsmagick 1.3.26-2 (bookworm)2017
CVE-2017-11139 [CRITICAL] CVE-2017-11139: graphicsmagick - GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() f... GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c. Scope: local bookworm: resolved (fixed in 1.3.26-2) bullseye: resolved (fixed in 1.3.26-2) forky: resolved (fixed in 1.3.26-2) sid: resolved (fixed in 1.3.26-2) trixie: resolved (fixed in 1.3.26-2)
debian
CVE-2019-11006P3CRITICALCVSS 9.1fixed in graphicsmagick 1.4~hg15968-1 (bookworm)2019
CVE-2019-11006 [CRITICAL] CVE-2019-11006: graphicsmagick - In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-re... In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the function ReadMIFFImage of coders/miff.c, which allows attackers to cause a denial of service or information disclosure via an RLE packet. Scope: local bookworm: resolved (fixed in 1.4~hg15968-1) bullseye: resolved (fixed in 1.4~hg15968-1) forky: resolved (fixed in 1.
debian
CVE-2017-16669P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-19 (bookworm)2017
CVE-2017-16669 [HIGH] CVE-2017-16669: graphicsmagick - coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial ... coders/wpg.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file, related to the AcquireCacheNexus function in magick/pixel_cache.c. Scope: local bookworm: resolved (fixed in 1.3.26-19) bullseye: resolved (fixed in 1.3.26-1
debian
CVE-2017-17498P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-17498 [HIGH] CVE-2017-17498: graphicsmagick - WritePNMImage in coders/pnm.c in GraphicsMagick 1.3.26 allows remote attackers t... WritePNMImage in coders/pnm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (bit_stream.c MagickBitStreamMSBWrite heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted file. Scope: local bookworm: resolved (fixed in 1.3.27-1) bullseye: resolved (fixed in 1.3.27-1) forky: resol
debian
CVE-2017-17500P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-17500 [HIGH] CVE-2017-17500: graphicsmagick - ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c Impo... ReadRGBImage in coders/rgb.c in GraphicsMagick 1.3.26 has a magick/import.c ImportRGBQuantumType heap-based buffer over-read via a crafted file. Scope: local bookworm: resolved (fixed in 1.3.27-1) bullseye: resolved (fixed in 1.3.27-1) forky: resolved (fixed in 1.3.27-1) sid: resolved (fixed in 1.3.27-1) trixie: resolved (fixed in 1.3.27-1)
debian
CVE-2017-17501P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-17501 [HIGH] CVE-2017-17501: graphicsmagick - WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffe... WriteOnePNGImage in coders/png.c in GraphicsMagick 1.3.26 has a heap-based buffer over-read via a crafted file. Scope: local bookworm: resolved (fixed in 1.3.27-1) bullseye: resolved (fixed in 1.3.27-1) forky: resolved (fixed in 1.3.27-1) sid: resolved (fixed in 1.3.27-1) trixie: resolved (fixed in 1.3.27-1)
debian
CVE-2017-17913P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-3 (bookworm)2017
CVE-2017-17913 [HIGH] CVE-2017-17913: graphicsmagick - In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-r... In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a stack-based buffer over-read in WriteWEBPImage in coders/webp.c, related to an incompatibility with libwebp versions, 0.5.0 and later, that use a different structure type. Scope: local bookworm: resolved (fixed in 1.3.27-3) bullseye: resolved (fixed in 1.3.27-3) forky: resolved (fixed in 1.3.27-3) sid: re
debian
Debian Graphicsmagick vulnerabilities | cvebase