Bug 1554194 (CVE-2017-18220) - CVE-2017-18220 GraphicsMagick: Use after free in ReadOneJNGImage and ReadJNGImage functions in coders/png.c allow an attacker to cause a denial of service via crafted file
Summary: CVE-2017-18220 GraphicsMagick: Use after free in ReadOneJNGImage and ReadJNGI...
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2017-18220
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1554188 1554189 1554195
Blocks:
TreeView+ depends on / blocked
 
Reported: 2018-03-12 03:45 UTC by Sam Fowler
Modified: 2019-09-29 14:35 UTC (History)
2 users (show)

Fixed In Version: GraphicsMagick 1.3.27
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2019-06-10 10:17:31 UTC
Embargoed:


Attachments (Terms of Use)

Description Sam Fowler 2018-03-12 03:45:24 UTC
GraphicsMagick through version 1.3.26 is vulnerable to a use after free in the ReadOneJNGImage and ReadJNGImage functions in coders/png.c. An attacker could exploit this to cause a denial of service via a crafted file.


Upstream Issue:

https://sourceforge.net/p/graphicsmagick/bugs/438/


Upstream Patch:

http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/98721124e51f

Comment 1 Sam Fowler 2018-03-12 03:46:23 UTC
Created GraphicsMagick tracking bugs for this issue:

Affects: fedora-all [bug 1554189]
Affects: epel-all [bug 1554188]


Note You need to log in before you can comment on or make changes to this bug.