CVE-2017-18219 PUBLISHED

An issue was discovered in GraphicsMagick 1.3.26. An allocation failure vulnerability was found in the function ReadOnePNGImage in coders/png.c, which allows attackers to cause a denial of service via a crafted file that triggers an attempt at a large png_pixels array allocation.

EPSS 5.97% · 90.6th percentile

Risk Scores

EPSS Score
5.97%
90.6th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:14.04:LTSgraphicsmagick0, 1.3.16-1.1ubuntu2, 1.3.16-1.1ubuntu3
Ubuntu:16.04:LTSgraphicsmagick0, 1.3.21-3, 1.3.23-1

Timeline

References

Open in Interactive Console →