Debian Graphicsmagick vulnerabilities
141 known vulnerabilities affecting debian/graphicsmagick.
Total CVEs
141
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL17HIGH47MEDIUM56LOW21
Vulnerabilities
Page 5 of 8
CVE-2007-4986P4MEDIUMCVSS 6.8fixed in graphicsmagick 1.1.11-1 (bookworm)2007
CVE-2007-4986 [MEDIUM] CVE-2007-4986: graphicsmagick - Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent...
Multiple integer overflows in ImageMagick before 6.3.5-9 allow context-dependent attackers to execute arbitrary code via a crafted (1) .dcm, (2) .dib, (3) .xbm, (4) .xcf, or (5) .xwd image file, which triggers a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.1.11-1)
bullseye: resolved (fixed in 1.1.11-1)
forky: resolved (fixed in 1.1.
debian
CVE-2017-17783P4HIGHCVSS 7.5fixed in graphicsmagick 1.3.27-2 (bookworm)2017
CVE-2017-17783 [HIGH] CVE-2017-17783: graphicsmagick - In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coder...
In GraphicsMagick 1.3.27a, there is a buffer over-read in ReadPALMImage in coders/palm.c when QuantumDepth is 8.
Scope: local
bookworm: resolved (fixed in 1.3.27-2)
bullseye: resolved (fixed in 1.3.27-2)
forky: resolved (fixed in 1.3.27-2)
sid: resolved (fixed in 1.3.27-2)
trixie: resolved (fixed in 1.3.27-2)
debian
CVE-2007-4988P4MEDIUMCVSS 7.8fixed in graphicsmagick 1.1.11-1 (bookworm)2007
CVE-2007-4988 [HIGH] CVE-2007-4988: graphicsmagick - Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 ...
Sign extension error in the ReadDIBImage function in ImageMagick before 6.3.5-9 allows context-dependent attackers to execute arbitrary code via a crafted width value in an image file, which triggers an integer overflow and a heap-based buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.1.11-1)
bullseye: resolved (fixed in 1.1.11-1)
forky: resolved (f
debian
CVE-2008-1096P4MEDIUMCVSS 6.8fixed in graphicsmagick 1.1.11-3.2 (bookworm)2008
CVE-2008-1096 [MEDIUM] CVE-2008-1096: graphicsmagick - The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8...
The load_tile function in the XCF coder in coders/xcf.c in (1) ImageMagick 6.2.8-0 and (2) GraphicsMagick (aka gm) 1.1.7 allows user-assisted remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted .xcf file that triggers an out-of-bounds heap write, possibly related to the ScaleCharToQuantum function.
Scope: loc
debian
CVE-2017-13064P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.26-7 (bookworm)2017
CVE-2017-13064 [MEDIUM] CVE-2017-13064: graphicsmagick - GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the func...
GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:12.
Scope: local
bookworm: resolved (fixed in 1.3.26-7)
bullseye: resolved (fixed in 1.3.26-7)
forky: resolved (fixed in 1.3.26-7)
sid: resolved (fixed in 1.3.26-7)
trixie: resolved (fixed in 1.3.26-7)
debian
CVE-2018-20184P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.4~hg15873-1 (bookworm)2018
CVE-2018-20184 [MEDIUM] CVE-2018-20184: graphicsmagick - In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflo...
In GraphicsMagick 1.4 snapshot-20181209 Q8, there is a heap-based buffer overflow in the WriteTGAImage function of tga.c, which allows attackers to cause a denial of service via a crafted image file, because the number of rows or columns can exceed the pixel-dimension restrictions of the TGA specification.
Scope: local
bookworm: resolved (fixed in 1.4~hg158
debian
CVE-2017-13063P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.26-7 (bookworm)2017
CVE-2017-13063 [MEDIUM] CVE-2017-13063: graphicsmagick - GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the func...
GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:314:12.
Scope: local
bookworm: resolved (fixed in 1.3.26-7)
bullseye: resolved (fixed in 1.3.26-7)
forky: resolved (fixed in 1.3.26-7)
sid: resolved (fixed in 1.3.26-7)
trixie: resolved (fixed in 1.3.26-7)
debian
CVE-2005-0397P4HIGHCVSS 7.5fixed in graphicsmagick 1.1.7-1 (bookworm)2005
CVE-2005-0397 [HIGH] CVE-2005-0397: graphicsmagick - Format string vulnerability in the SetImageInfo function in image.c for ImageMag...
Format string vulnerability in the SetImageInfo function in image.c for ImageMagick before 6.0.2.5 may allow remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in a filename argument to convert, which may be called by other web applications.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2008-6621P4HIGHCVSS 7.8fixed in graphicsmagick 1.2.3-1 (bookworm)2008
CVE-2008-6621 [HIGH] CVE-2008-6621: graphicsmagick - Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers...
Unspecified vulnerability in GraphicsMagick before 1.2.3 allows remote attackers to cause a denial of service (crash) via unspecified vectors in DPX images. NOTE: some of these details are obtained from third party information.
Scope: local
bookworm: resolved (fixed in 1.2.3-1)
bullseye: resolved (fixed in 1.2.3-1)
forky: resolved (fixed in 1.2.3-1)
sid: resolv
debian
CVE-2017-18219P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-18219 [MEDIUM] CVE-2017-18219: graphicsmagick - An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerab...
An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadOnePNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted file that triggers an attempt at a large png_pixels array allocation.
Scope: local
bookworm: resolved (fixed in 1.3.27-1)
bullseye: resolved (fixed
debian
CVE-2017-14997P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.26-13 (bookworm)2017
CVE-2017-14997 [MEDIUM] CVE-2017-14997: graphicsmagick - GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (exce...
GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (excessive memory allocation) because of an integer underflow in ReadPICTImage in coders/pict.c.
Scope: local
bookworm: resolved (fixed in 1.3.26-13)
bullseye: resolved (fixed in 1.3.26-13)
forky: resolved (fixed in 1.3.26-13)
sid: resolved (fixed in 1.3.26-13)
trixie: resolved (fixe
debian
CVE-2017-13737P4LOWCVSS 6.5fixed in graphicsmagick 1.3.26-15 (bookworm)2017
CVE-2017-13737 [MEDIUM] CVE-2017-13737: graphicsmagick - There is an invalid free in the MagickFree function in magick/memory.c in Graphi...
There is an invalid free in the MagickFree function in magick/memory.c in GraphicsMagick 1.3.26 that will lead to a remote denial of service attack.
Scope: local
bookworm: resolved (fixed in 1.3.26-15)
bullseye: resolved (fixed in 1.3.26-15)
forky: resolved (fixed in 1.3.26-15)
sid: resolved (fixed in 1.3.26-15)
trixie: resolved (fixed in 1.3.26-15)
debian
CVE-2018-20189P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.4~hg15873-1 (bookworm)2018
CVE-2018-20189 [MEDIUM] CVE-2018-20189: graphicsmagick - In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulner...
In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bits/sample), and therefore lacks indexes initialization.
Scope: local
bookworm: resolved (fixed in 1.4~hg15873
debian
CVE-2017-14994P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.26-13 (bookworm)2017
CVE-2017-14994 [MEDIUM] CVE-2017-14994: graphicsmagick - ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to...
ReadDCMImage in coders/dcm.c in GraphicsMagick 1.3.26 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted DICOM image, related to the ability of DCM_ReadNonNativeImages to yield an image list with zero frames.
Scope: local
bookworm: resolved (fixed in 1.3.26-13)
bullseye: resolved (fixed in 1.3.26-13)
forky: resolve
debian
CVE-2017-14042P4LOWCVSS 6.5fixed in graphicsmagick 1.3.26-9 (bookworm)2017
CVE-2017-14042 [MEDIUM] CVE-2017-14042: graphicsmagick - A memory allocation failure was discovered in the ReadPNMImage function in coder...
A memory allocation failure was discovered in the ReadPNMImage function in coders/pnm.c in GraphicsMagick 1.3.26. The vulnerability causes a big memory allocation, which may lead to remote denial of service in the MagickRealloc function in magick/memory.c.
Scope: local
bookworm: resolved (fixed in 1.3.26-9)
bullseye: resolved (fixed in 1.3.26-9)
forky: reso
debian
CVE-2017-13776P4LOWCVSS 6.5fixed in graphicsmagick 1.3.26-8 (bookworm)2017
CVE-2017-13776 [MEDIUM] CVE-2017-13776: graphicsmagick - GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coder...
GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version!=10 case that results in the reader not returning; it would cause large amounts of CPU and memory consumption although the crafted file itself does not request it.
Scope: local
bookworm: resolved (fixed in 1.3.26-8)
bullseye: resolved (fixed
debian
CVE-2017-18229P4MEDIUMCVSS 6.5fixed in graphicsmagick 1.3.27-1 (bookworm)2017
CVE-2017-18229 [MEDIUM] CVE-2017-18229: graphicsmagick - An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerab...
An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadTIFFImage in coders/tiff.c, which allows attackers to cause a denial of service via a crafted file, because file size is not properly used to restrict scanline, strip, and tile allocations.
Scope: local
bookworm: resolved (fixed in 1.3.27-1)
b
debian
CVE-2017-14165P4LOWCVSS 6.5fixed in graphicsmagick 1.3.26-9 (bookworm)2017
CVE-2017-14165 [MEDIUM] CVE-2017-14165: graphicsmagick - The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has an issue ...
The ReadSUNImage function in coders/sun.c in GraphicsMagick 1.3.26 has an issue where memory allocation is excessive because it depends only on a length field in a header. This may lead to remote denial of service in the MagickMalloc function in magick/memory.c.
Scope: local
bookworm: resolved (fixed in 1.3.26-9)
bullseye: resolved (fixed in 1.3.26-9)
forky
debian
CVE-2017-13777P4LOWCVSS 6.5fixed in graphicsmagick 1.3.26-8 (bookworm)2017
CVE-2017-13777 [MEDIUM] CVE-2017-13777: graphicsmagick - GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coder...
GraphicsMagick 1.3.26 has a denial of service issue in ReadXBMImage() in a coders/xbm.c "Read hex image data" version==10 case that results in the reader not returning; it would cause large amounts of CPU and memory consumption although the crafted file itself does not request it.
Scope: local
bookworm: resolved (fixed in 1.3.26-8)
bullseye: resolved (fixed
debian
CVE-2017-13775P4LOWCVSS 6.5fixed in graphicsmagick 1.3.26-8 (bookworm)2017
CVE-2017-13775 [MEDIUM] CVE-2017-13775: graphicsmagick - GraphicsMagick 1.3.26 has a denial of service issue in ReadJNXImage() in coders/...
GraphicsMagick 1.3.26 has a denial of service issue in ReadJNXImage() in coders/jnx.c whereby large amounts of CPU and memory resources may be consumed although the file itself does not support the requests.
Scope: local
bookworm: resolved (fixed in 1.3.26-8)
bullseye: resolved (fixed in 1.3.26-8)
forky: resolved (fixed in 1.3.26-8)
sid: resolved (fixed in
debian