Denial of Service in GraphicsMagick Affects Multiple Platforms
CVE-2019-11473

6.5MEDIUM

Key Information:

Vendor
CVE Published:
23 April 2019

What is CVE-2019-11473?

The vulnerability in GraphicsMagick 1.3.31 permits attackers to induce a denial of service by exploiting a flaw in the processing of XWD image files. By delivering a specially crafted XWD file, an out-of-bounds read can occur, leading to an unexpected application crash. This issue is distinct from other vulnerabilities reported in the same timeframe, such as CVE-2019-11008 and CVE-2019-11009, highlighting the need for vigilance in file handling and image processing.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.