Buffer Overflow Vulnerability in GraphicsMagick Affects Remote System Stability
CVE-2019-11005

9.8CRITICAL

Key Information:

Vendor
CVE Published:
8 April 2019

What is CVE-2019-11005?

A buffer overflow vulnerability exists in GraphicsMagick version 1.4 snapshot-20190322 Q8, specifically within the SVGStartElement function in the coders/svg.c file. This flaw can be exploited by remote attackers through a crafted SVG file that includes a malicious quoted font family value, potentially causing the application to crash and leading to service disruptions. The issue emphasizes the need for rigorous input validation in graphics processing libraries.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.