Bug 1554187 (CVE-2017-18219) - CVE-2017-18219 GraphicsMagick: Memory allocation failure in coders/png.c:ReadOnePNGImage() allows for denial of service via crafted file
Summary: CVE-2017-18219 GraphicsMagick: Memory allocation failure in coders/png.c:Read...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2017-18219
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1554188 1554189 1554192 1554195
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-03-12 03:36 UTC by Sam Fowler
Modified: 2019-09-29 14:35 UTC (History)
2 users (show)

Fixed In Version: GraphicsMagick 1.3.27
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-06-10 10:17:29 UTC
Embargoed:


Attachments (Terms of Use)

Description Sam Fowler 2018-03-12 03:36:11 UTC
GraphicsMagick through version 1.3.26 is vulnerable to a memory allocation failure in coders/png.c:ReadOnePNGImage(). An attacker could cause a denial of service via a crafted file that triggers an attempt at a large png_pixels array allocation.


Upstream Issue:

https://sourceforge.net/p/graphicsmagick/bugs/459/


Upstream Patch:

http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/cadd4b0522fa

Comment 1 Sam Fowler 2018-03-12 03:36:33 UTC
Created GraphicsMagick tracking bugs for this issue:

Affects: fedora-all [bug 1554189]
Affects: epel-all [bug 1554188]


Note You need to log in before you can comment on or make changes to this bug.