CVE-2013-4589: Medium severity suse linux enterprise software development kit vulnerability
GraphicsMagick, a comprehensive image processing package, is found to have a vulnerability which can be exploited by malicious people to cause a Denial of Service (DoS).
The vulnerability is caused due to an error within the "ExportAlphaQuantumType()" function found in magick/export.c when exporting 8-bit RGBA images, which can be exploited to cause a crash.
The vulnerability is reported in versions prior to 1.3.18, Fedora 19 already ships with 1.3.18, so it doesn't seem to be affected.
References: https://bugs.gentoo.org/showbug.cgi?id=488050
Other sources
The ExportAlphaQuantumType function in export.c in GraphicsMagick before 1.3.18 might allow remote attackers to cause a denial of service (crash) via vectors related to exporting the alpha of an 8-bit RGBA image.
— MITRE
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4589?
CVE-2013-4589 is classified as a Denial of Service (DoS) vulnerability.
How do I fix CVE-2013-4589?
To fix CVE-2013-4589, upgrade GraphicsMagick to version 1.3.18 or later.
What versions of GraphicsMagick are affected by CVE-2013-4589?
Versions of GraphicsMagick up to 1.3.17 are affected by CVE-2013-4589.
Are there any specific distributions affected by CVE-2013-4589?
CVE-2013-4589 affects several distributions including Red Hat and SUSE Linux.
What component is responsible for the vulnerability CVE-2013-4589?
The vulnerability CVE-2013-4589 is caused by an error in the 'ExportAlphaQuantumType()' function in GraphicsMagick.