Buffer Over-read Vulnerability in GraphicsMagick by Artifex Software
CVE-2017-17783

7.5HIGH

Key Information:

Vendor
CVE Published:
20 December 2017

What is CVE-2017-17783?

A buffer over-read vulnerability exists in GraphicsMagick version 1.3.27a, specifically in the 'ReadPALMImage' function located in coders/palm.c. When the QuantumDepth is set to 8, the code can read past the intended buffer, potentially exposing sensitive information or leading to unexpected behavior. This flaw emphasizes the importance of updating to secure versions to mitigate risks associated with unexpected inputs.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.