Heap-Based Buffer Over-Read in GraphicsMagick Affects Multiple Versions
CVE-2017-17782

8.8HIGH

Key Information:

Vendor
CVE Published:
20 December 2017

What is CVE-2017-17782?

In GraphicsMagick version 1.3.27a, a heap-based buffer over-read vulnerability exists in the ReadOneJNGImage function implemented in the coders/png.c file. This security issue originates from improper handling of the oFFs chunk allocation, which could potentially allow an attacker to exploit this flaw and gain unauthorized access to sensitive information or cause application instability.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.