First published: Mon Jul 10 2017(Updated: )
GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
debian/graphicsmagick | 1.4+really1.3.35-1~deb10u2 1.4+really1.3.35-1~deb10u3 1.4+really1.3.36+hg16481-2+deb11u1 1.4+really1.3.40-4 1.4+really1.3.42-1 | |
GraphicsMagick | =1.3.26 | |
Debian Debian Linux | =9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-11139 has been classified as a medium severity vulnerability due to the potential for a crash or denial of service.
To remediate CVE-2017-11139, upgrade to GraphicsMagick version 1.4+really1.3.35-1~deb10u2 or later.
CVE-2017-11139 affects GraphicsMagick version 1.3.26.
CVE-2017-11139 is particularly noted for its impact on Debian Linux.
CVE-2017-11139 involves double free vulnerabilities within the ReadOneJNGImage() function of GraphicsMagick.