Debian Graphicsmagick vulnerabilities
141 known vulnerabilities affecting debian/graphicsmagick.
Total CVEs
141
CISA KEV
3
actively exploited
Public exploits
9
Exploited in wild
3
Severity breakdown
CRITICAL17HIGH47MEDIUM56LOW21
Vulnerabilities
Page 7 of 8
CVE-2018-20185P4MEDIUMCVSS 5.3fixed in graphicsmagick 1.4~hg15880-1 (bookworm)2018
CVE-2018-20185 [MEDIUM] CVE-2018-20185: graphicsmagick - In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-...
In GraphicsMagick 1.4 snapshot-20181209 Q8 on 32-bit platforms, there is a heap-based buffer over-read in the ReadBMPImage function of bmp.c, which allows attackers to cause a denial of service via a crafted bmp image file. This only affects GraphicsMagick installations with customized BMP limits.
Scope: local
bookworm: resolved (fixed in 1.4~hg15880-1)
bul
debian
CVE-2014-8355P4MEDIUMCVSS 5.5fixed in graphicsmagick 1.3.20-3+deb8u1 (bookworm)2014
CVE-2014-8355 [MEDIUM] CVE-2014-8355: graphicsmagick - PCX parser code in ImageMagick before 6.8.9-9 allows remote attackers to cause a...
PCX parser code in ImageMagick before 6.8.9-9 allows remote attackers to cause a denial of service (out-of-bounds read).
Scope: local
bookworm: resolved (fixed in 1.3.20-3+deb8u1)
bullseye: resolved (fixed in 1.3.20-3+deb8u1)
forky: resolved (fixed in 1.3.20-3+deb8u1)
sid: resolved (fixed in 1.3.20-3+deb8u1)
trixie: resolved (fixed in 1.3.20-3+deb8u1)
debian
CVE-2016-2317P4MEDIUMCVSS 5.5fixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-2317 [MEDIUM] CVE-2016-2317: graphicsmagick - Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cau...
Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in magick/utility.c, and (3) GetTransformTokens function in coders/svg.c.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved
debian
CVE-2016-2318P4MEDIUMCVSS 5.5fixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-2318 [MEDIUM] CVE-2016-2318: graphicsmagick - GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL...
GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath function in magick/render.c.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in
debian
CVE-2017-11140P4LOWCVSS 5.5fixed in graphicsmagick 1.3.26-3 (bookworm)2017
CVE-2017-11140 [MEDIUM] CVE-2017-11140: graphicsmagick - The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a p...
The ReadJPEGImage function in coders/jpeg.c in GraphicsMagick 1.3.26 creates a pixel cache before a successful read of a scanline, which allows remote attackers to cause a denial of service (resource consumption) via crafted JPEG files.
Scope: local
bookworm: resolved (fixed in 1.3.26-3)
bullseye: resolved (fixed in 1.3.26-3)
forky: resolved (fixed in 1.3.2
debian
CVE-2017-10794P4MEDIUMCVSS 5.5fixed in graphicsmagick 1.3.26-1 (bookworm)2017
CVE-2017-10794 [MEDIUM] CVE-2017-10794: graphicsmagick - When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicati...
When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/tiff.c, a buffer overflow occurs, related to QuantumTransferMode.
Scope: local
bookworm: resolved (fixed in 1.3.26-1)
bullseye: resolved (fixed in 1.3.26-1)
forky: resolved (fixed in 1.3.26-1)
sid: resolved (fixed in 1.3.26-1)
trixie: reso
debian
CVE-2009-3736P4LOWCVSS 6.9fixed in clamav 0.95+dfsg-1 (bookworm)2009
CVE-2009-3736 [MEDIUM] CVE-2009-3736: bochs - ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham ...
ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2016-9830P4MEDIUMCVSS 5.5fixed in graphicsmagick 1.3.25-6 (bookworm)2016
CVE-2016-9830 [MEDIUM] CVE-2016-9830: graphicsmagick - The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote at...
The MagickRealloc function in memory.c in Graphicsmagick 1.3.25 allows remote attackers to cause a denial of service (crash) via large dimensions in a jpeg image.
Scope: local
bookworm: resolved (fixed in 1.3.25-6)
bullseye: resolved (fixed in 1.3.25-6)
forky: resolved (fixed in 1.3.25-6)
sid: resolved (fixed in 1.3.25-6)
trixie: resolved (fixed in 1.3.25-6)
debian
CVE-2008-3134P4MEDIUMCVSS 5.0fixed in graphicsmagick 1.2.4-1 (bookworm)2008
CVE-2008-3134 [MEDIUM] CVE-2008-3134: graphicsmagick - Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote...
Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/im
debian
CVE-2015-8808P4MEDIUMCVSS 5.5fixed in graphicsmagick 1.3.21-2 (bookworm)2015
CVE-2015-8808 [MEDIUM] CVE-2015-8808: graphicsmagick - The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote ...
The DecodeImage function in coders/gif.c in GraphicsMagick 1.3.18 allows remote attackers to cause a denial of service (uninitialized memory access) via a crafted GIF file.
Scope: local
bookworm: resolved (fixed in 1.3.21-2)
bullseye: resolved (fixed in 1.3.21-2)
forky: resolved (fixed in 1.3.21-2)
sid: resolved (fixed in 1.3.21-2)
trixie: resolved (fixed in
debian
CVE-2020-21679P4MEDIUMCVSS 5.5fixed in graphicsmagick 1.4+really1.3.34+hg16181-1 (bookworm)2020
CVE-2020-21679 [MEDIUM] CVE-2020-21679: graphicsmagick - Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagi...
Buffer Overflow vulnerability in WritePCXImage function in pcx.c in GraphicsMagick 1.4 allows remote attackers to cause a denial of service via converting of crafted image file to pcx format.
Scope: local
bookworm: resolved (fixed in 1.4+really1.3.34+hg16181-1)
bullseye: resolved (fixed in 1.4+really1.3.34+hg16181-1)
forky: resolved (fixed in 1.4+really1.3.
debian
CVE-2016-5240P4MEDIUMCVSS 5.5fixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-5240 [MEDIUM] CVE-2016-5240: graphicsmagick - The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 ...
The DrawDashPolygon function in magick/render.c in GraphicsMagick before 1.3.24 and the SVG renderer in ImageMagick allow remote attackers to cause a denial of service (infinite loop) by converting a circularly defined SVG file.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid:
debian
CVE-2017-6335P4MEDIUMCVSS 5.5fixed in graphicsmagick 1.3.25-8 (bookworm)2017
CVE-2017-6335 [MEDIUM] CVE-2017-6335: graphicsmagick - The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and e...
The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a small samples per pixel value in a CMYKA TIFF file.
Scope: local
bookworm: resolved (fixed in 1.3.25-8)
bullseye: resolved (fixed in 1.3.25-8)
forky: resolved (fixed in 1.3
debian
CVE-2017-14649P4LOWCVSS 5.5fixed in graphicsmagick 1.3.26-12 (bookworm)2017
CVE-2017-14649 [MEDIUM] CVE-2017-14649: graphicsmagick - ReadOneJNGImage in coders/png.c in GraphicsMagick version 1.3.26 does not proper...
ReadOneJNGImage in coders/png.c in GraphicsMagick version 1.3.26 does not properly validate JNG data, leading to a denial of service (assertion failure in magick/pixel_cache.c, and application crash).
Scope: local
bookworm: resolved (fixed in 1.3.26-12)
bullseye: resolved (fixed in 1.3.26-12)
forky: resolved (fixed in 1.3.26-12)
sid: resolved (fixed in 1.3.
debian
CVE-2017-10800P4MEDIUMCVSS 5.5fixed in graphicsmagick 1.3.26-1 (bookworm)2017
CVE-2017-10800 [MEDIUM] CVE-2017-10800: graphicsmagick - When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead...
When GraphicsMagick 1.3.25 processes a MATLAB image in coders/mat.c, it can lead to a denial of service (OOM) in ReadMATImage() if the size specified for a MAT Object is larger than the actual amount of data.
Scope: local
bookworm: resolved (fixed in 1.3.26-1)
bullseye: resolved (fixed in 1.3.26-1)
forky: resolved (fixed in 1.3.26-1)
sid: resolved (fixed in
debian
CVE-2013-4589P4LOWCVSS 4.3fixed in graphicsmagick 1.3.18-1 (bookworm)2013
CVE-2013-4589 [MEDIUM] CVE-2013-4589: graphicsmagick - The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 ...
The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.
Scope: local
bookworm: resolved (fixed in 1.3.18-1)
bullseye: resolved (fixed in 1.3.18-1)
forky: resolved (fixed in 1.3.18-1)
sid: resolved (fixed
debian
CVE-2008-6072P4MEDIUMCVSS 5.0fixed in graphicsmagick 1.2.3-1 (bookworm)2008
CVE-2008-6072 [MEDIUM] CVE-2008-6072: graphicsmagick - Multiple unspecified vulnerabilities in GraphicsMagick before 1.1.14, and 1.2.x ...
Multiple unspecified vulnerabilities in GraphicsMagick before 1.1.14, and 1.2.x before 1.2.3, allow remote attackers to cause a denial of service (crash) via unspecified vectors in (1) XCF and (2) CINEON images.
Scope: local
bookworm: resolved (fixed in 1.2.3-1)
bullseye: resolved (fixed in 1.2.3-1)
forky: resolved (fixed in 1.2.3-1)
sid: resolved (fixed in 1
debian
CVE-2017-10799P4MEDIUMCVSS 5.5fixed in graphicsmagick 1.3.26-1 (bookworm)2017
CVE-2017-10799 [MEDIUM] CVE-2017-10799: graphicsmagick - When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a lar...
When GraphicsMagick 1.3.25 processes a DPX image (with metadata indicating a large width) in coders/dpx.c, a denial of service (OOM) can occur in ReadDPXImage().
Scope: local
bookworm: resolved (fixed in 1.3.26-1)
bullseye: resolved (fixed in 1.3.26-1)
forky: resolved (fixed in 1.3.26-1)
sid: resolved (fixed in 1.3.26-1)
trixie: resolved (fixed in 1.3.26-1)
debian
CVE-2016-5241P4MEDIUMCVSS 5.5fixed in graphicsmagick 1.3.24-1 (bookworm)2016
CVE-2016-5241 [MEDIUM] CVE-2016-5241: graphicsmagick - magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause...
magick/render.c in GraphicsMagick before 1.3.24 allows remote attackers to cause a denial of service (arithmetic exception and application crash) via a crafted svg file.
Scope: local
bookworm: resolved (fixed in 1.3.24-1)
bullseye: resolved (fixed in 1.3.24-1)
forky: resolved (fixed in 1.3.24-1)
sid: resolved (fixed in 1.3.24-1)
trixie: resolved (fixed in 1.3
debian
CVE-2012-3438P4LOWCVSS 4.3fixed in graphicsmagick 1.3.16-1.1 (bookworm)2012
CVE-2012-3438 [MEDIUM] CVE-2012-3438: graphicsmagick - The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does no...
The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation.
Scope: local
bookworm: resolved (fixed in 1.3.16-1.1)
bullseye: resolved (fixed in 1.3.
debian