Debian Graphicsmagick vulnerabilities
141 known vulnerabilities affecting debian/graphicsmagick.
Total CVEs
141
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL17HIGH47MEDIUM56LOW21
Vulnerabilities
Page 3 of 8
CVE-2020-12672P3HIGHCVSS 7.5fixed in graphicsmagick 1.4+really1.3.35-2 (bookworm)2020
CVE-2020-12672 [HIGH] CVE-2020-12672: graphicsmagick - GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage i...
GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.35-2)
bullseye: resolved (fixed in 1.4+really1.3.35-2)
forky: resolved (fixed in 1.4+really1.3.35-2)
sid: resolved (fixed in 1.4+really1.3.35-2)
trixie: resolved (fixed in 1.4+really1.3.35-2)
debian
CVE-2017-18220P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-8 (bookworm)2017
CVE-2017-18220 [HIGH] CVE-2017-18220: graphicsmagick - The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick...
The ReadOneJNGImage and ReadJNGImage functions in coders/png.c in GraphicsMagick 1.3.26 allow remote attackers to cause a denial of service (magick/blob.c CloseBlob use-after-free) or possibly have unspecified other impact via a crafted file, a related issue to CVE-2017-11403.
Scope: local
bookworm: resolved (fixed in 1.3.26-8)
bullseye: resolved (fixed in 1.
debian
CVE-2019-19953P3CRITICALCVSS 9.1fixed in graphicsmagick 1.4+really1.3.34-1 (bookworm)2019
CVE-2019-19953 [CRITICAL] CVE-2019-19953: graphicsmagick - In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-re...
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.34-1)
bullseye: resolved (fixed in 1.4+really1.3.34-1)
forky: resolved (fixed in 1.4+really1.3.34-1)
sid: resolved (fixed in 1.4+really1.3.34-1)
trixie: resolved (fixed in
debian
CVE-2017-17503P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-17503 [HIGH] CVE-2017-17503: graphicsmagick - ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c Im...
ReadGRAYImage in coders/gray.c in GraphicsMagick 1.3.26 has a magick/import.c ImportGrayQuantumType heap-based buffer over-read via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.3.27-1)
bullseye: resolved (fixed in 1.3.27-1)
forky: resolved (fixed in 1.3.27-1)
sid: resolved (fixed in 1.3.27-1)
trixie: resolved (fixed in 1.3.27-1)
debian
CVE-2017-17502P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-17502 [HIGH] CVE-2017-17502: graphicsmagick - ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c Im...
ReadCMYKImage in coders/cmyk.c in GraphicsMagick 1.3.26 has a magick/import.c ImportCMYKQuantumType heap-based buffer over-read via a crafted file.
Scope: local
bookworm: resolved (fixed in 1.3.27-1)
bullseye: resolved (fixed in 1.3.27-1)
forky: resolved (fixed in 1.3.27-1)
sid: resolved (fixed in 1.3.27-1)
trixie: resolved (fixed in 1.3.27-1)
debian
CVE-2017-11642P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-4 (bookworm)2017
CVE-2017-11642 [HIGH] CVE-2017-11642: graphicsmagick - GraphicsMagick 1.3.26 has a NULL pointer dereference in the WriteMAPImage() func...
GraphicsMagick 1.3.26 has a NULL pointer dereference in the WriteMAPImage() function in coders/map.c when processing a non-colormapped image, a different vulnerability than CVE-2017-11638.
Scope: local
bookworm: resolved (fixed in 1.3.26-4)
bullseye: resolved (fixed in 1.3.26-4)
forky: resolved (fixed in 1.3.26-4)
sid: resolved (fixed in 1.3.26-4)
trixie: res
debian
CVE-2017-15930P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-16 (bookworm)2017
CVE-2017-15930 [HIGH] CVE-2017-15930: graphicsmagick - In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dere...
In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelPacket pointer.
Scope: local
bookworm: resolved (fixed in 1.3.26-16)
bullseye: resolved (fixed in 1.3.26-16)
forky: resolved (fixed in 1.3.26-16)
sid: resolved (fixed in 1.3.26-16)
trixie: resolved (fixed in 1.3.2
debian
CVE-2017-17915P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-3 (bookworm)2017
CVE-2017-17915 [HIGH] CVE-2017-17915: graphicsmagick - In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-re...
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadMNGImage in coders/png.c, related to accessing one byte before testing whether a limit has been reached.
Scope: local
bookworm: resolved (fixed in 1.3.27-3)
bullseye: resolved (fixed in 1.3.27-3)
forky: resolved (fixed in 1.3.27-3)
sid: resolved (fixed in 1.3.27-3)
trixi
debian
CVE-2017-17912P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-3 (bookworm)2017
CVE-2017-17912 [HIGH] CVE-2017-17912: graphicsmagick - In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-re...
In GraphicsMagick 1.4 snapshot-20171217 Q8, there is a heap-based buffer over-read in ReadNewsProfile in coders/tiff.c, in which LocaleNCompare reads heap data beyond the allocated region.
Scope: local
bookworm: resolved (fixed in 1.3.27-3)
bullseye: resolved (fixed in 1.3.27-3)
forky: resolved (fixed in 1.3.27-3)
sid: resolved (fixed in 1.3.27-3)
trixie: res
debian
CVE-2017-11638P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-4 (bookworm)2017
CVE-2017-11638 [HIGH] CVE-2017-11638: graphicsmagick - GraphicsMagick 1.3.26 has a segmentation violation in the WriteMAPImage() functi...
GraphicsMagick 1.3.26 has a segmentation violation in the WriteMAPImage() function in coders/map.c when processing a non-colormapped image, a different vulnerability than CVE-2017-11642.
Scope: local
bookworm: resolved (fixed in 1.3.26-4)
bullseye: resolved (fixed in 1.3.26-4)
forky: resolved (fixed in 1.3.26-4)
sid: resolved (fixed in 1.3.26-4)
trixie: resol
debian
CVE-2019-7397P3LOWCVSS 7.5fixed in graphicsmagick 1.4~hg15896-1 (bookworm)2019
CVE-2019-7397 [HIGH] CVE-2019-7397: graphicsmagick - In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory...
In ImageMagick before 7.0.8-25 and GraphicsMagick through 1.3.31, several memory leaks exist in WritePDFImage in coders/pdf.c.
Scope: local
bookworm: resolved (fixed in 1.4~hg15896-1)
bullseye: resolved (fixed in 1.4~hg15896-1)
forky: resolved (fixed in 1.4~hg15896-1)
sid: resolved (fixed in 1.4~hg15896-1)
trixie: resolved (fixed in 1.4~hg15896-1)
debian
CVE-2025-32460P3MEDIUMCVSS 4.0fixed in graphicsmagick 1.4+really1.3.40-4+deb12u1 (bookworm)2025
CVE-2025-32460 [MEDIUM] CVE-2025-32460: graphicsmagick - GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage ...
GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.40-4+deb12u1)
bullseye: resolved
forky: resolved (fixed in 1.4+really1.3.45+hg17696-1)
sid: resolved (fixed in 1.4+really1.3.45+hg17696-1)
trixie: resolved (fixed in
debian
CVE-2018-6799P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.28-1 (bookworm)2018
CVE-2018-6799 [HIGH] CVE-2018-6799: graphicsmagick - The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before ...
The AcquireCacheNexus function in magick/pixel_cache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging area is not used.
Scope: local
bookworm: resolved (fixed in 1.3.28-1)
bullseye: resolved (fixed in 1.3.28-1)
forky
debian
CVE-2017-12937P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-6 (bookworm)2017
CVE-2017-12937 [HIGH] CVE-2017-12937: graphicsmagick - The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colorma...
The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has a colormap heap-based buffer over-read.
Scope: local
bookworm: resolved (fixed in 1.3.26-6)
bullseye: resolved (fixed in 1.3.26-6)
forky: resolved (fixed in 1.3.26-6)
sid: resolved (fixed in 1.3.26-6)
trixie: resolved (fixed in 1.3.26-6)
debian
CVE-2017-12935P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-6 (bookworm)2017
CVE-2017-12935 [HIGH] CVE-2017-12935: graphicsmagick - The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles la...
The ReadMNGImage function in coders/png.c in GraphicsMagick 1.3.26 mishandles large MNG images, leading to an invalid memory read in the SetImageColorCallBack function in magick/image.c.
Scope: local
bookworm: resolved (fixed in 1.3.26-6)
bullseye: resolved (fixed in 1.3.26-6)
forky: resolved (fixed in 1.3.26-6)
sid: resolved (fixed in 1.3.26-6)
trixie: resol
debian
CVE-2017-17782P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.27-2 (bookworm)2017
CVE-2017-17782 [HIGH] CVE-2017-17782: graphicsmagick - In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGI...
In GraphicsMagick 1.3.27a, there is a heap-based buffer over-read in ReadOneJNGImage in coders/png.c, related to oFFs chunk allocation.
Scope: local
bookworm: resolved (fixed in 1.3.27-2)
bullseye: resolved (fixed in 1.3.27-2)
forky: resolved (fixed in 1.3.27-2)
sid: resolved (fixed in 1.3.27-2)
trixie: resolved (fixed in 1.3.27-2)
debian
CVE-2017-13147P3LOWCVSS 8.8fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-13147 [HIGH] CVE-2017-13147: graphicsmagick - In GraphicsMagick 1.3.26, an allocation failure vulnerability was found in the f...
In GraphicsMagick 1.3.26, an allocation failure vulnerability was found in the function ReadMNGImage in coders/png.c when a small MNG file has a MEND chunk with a large length value.
Scope: local
bookworm: resolved (fixed in 1.3.27-1)
bullseye: resolved (fixed in 1.3.27-1)
forky: resolved (fixed in 1.3.27-1)
sid: resolved (fixed in 1.3.27-1)
trixie: resolved
debian
CVE-2016-7800P3HIGHCVSS 7.5fixed in graphicsmagick 1.3.25-3 (bookworm)2016
CVE-2016-7800 [HIGH] CVE-2016-7800: graphicsmagick - Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1...
Integer underflow in the parse8BIM function in coders/meta.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (application crash) via a crafted 8BIM chunk, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.3.25-3)
bullseye: resolved (fixed in 1.3.25-3)
forky: resolved (fixed in 1.3.
debian
CVE-2008-6070P3CRITICALCVSS 9.3fixed in graphicsmagick 1.2.3-1 (bookworm)2008
CVE-2008-6070 [CRITICAL] CVE-2008-6070: graphicsmagick - Multiple heap-based buffer underflows in the ReadPALMImage function in coders/pa...
Multiple heap-based buffer underflows in the ReadPALMImage function in coders/palm.c in GraphicsMagick before 1.2.3 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted PALM image, a different vulnerability than CVE-2007-0770. NOTE: some of these details are obtained from third party information.
Scope
debian
CVE-2017-15238P3HIGHCVSS 8.8fixed in graphicsmagick 1.3.26-14 (bookworm)2017
CVE-2017-15238 [HIGH] CVE-2017-15238: graphicsmagick - ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free is...
ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26 has a use-after-free issue when the height or width is zero, related to ReadJNGImage.
Scope: local
bookworm: resolved (fixed in 1.3.26-14)
bullseye: resolved (fixed in 1.3.26-14)
forky: resolved (fixed in 1.3.26-14)
sid: resolved (fixed in 1.3.26-14)
trixie: resolved (fixed in 1.3.26-14)
debian