CVE-2018-20189 PUBLISHED

In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bits/sample), and therefore lacks indexes initialization.

EPSS 0.63% · 70.2th percentile

Risk Scores

EPSS Score
0.63%
70.2th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:16.04:LTSgraphicsmagick0, 1.3.23-1ubuntu0.6+esm1, 1.3.23-1ubuntu0.6
Ubuntu:18.04:LTSgraphicsmagick1.3.28-2, 0, 1.3.26-15
Ubuntu:Pro:14.04:LTSgraphicsmagick1.3.18-1ubuntu3, 1.3.16-1.1ubuntu3, 1.3.16-1.1ubuntu2

Timeline

References

Open in Interactive Console →