ZeroHour

CVE-2018-20189

PoC
CVSS 3.0
6.5 medium
EPSS
2%p82
Published
()
Modified
Description

In GraphicsMagick 1.3.31, the ReadDIBImage function of coders/dib.c has a vulnerability allowing a crash and denial of service via a dib file that is crafted to appear with direct pixel values and also colormapping (which is not available beyond 8-bits/sample), and therefore lacks indexes initialization.

Vendors
graphicsmagickdebian
Products
graphicsmagick, debian linux
Weakness
CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.