CVE-2017-13064: Buffer Overflow
Published Aug 22, 2017
·Updated
GraphicsMagick 1.3.26 has a heap-based buffer overflow vulnerability in the function GetStyleTokens in coders/svg.c:311:12.
Affected Software
4 affected componentsFixes available
GraphicsMagick Graphicsmagick=1.3.26
Debian Debian Linux=8.0
Debian Debian Linux=9.0
debian/graphicsmagick
1.4+really1.3.36+hg16481-2+deb11u11.4+really1.3.40-4+deb12u11.4+really1.3.45+hg17696-11.4+really1.3.46-2
Event History
Aug 22, 2017
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Feb 19, 2026
Data Sourced
via Ubuntu·08:20 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·08:21 PM
DescriptionAffected Software
Data Sourced
via Launchpad·08:21 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-13064?
The severity of CVE-2017-13064 is medium with a severity value of 6.5.
2
What software is affected by CVE-2017-13064?
GraphicsMagick 1.3.26 and Debian Linux 8.0 and 9.0 are affected by CVE-2017-13064.
3
How can I mitigate CVE-2017-13064?
To mitigate CVE-2017-13064, update GraphicsMagick to version 1.4+really1.3.35-1~deb10u2 or later.
4
Where can I find more information about CVE-2017-13064?
You can find more information about CVE-2017-13064 at the following references: http://hg.code.sf.net/p/graphicsmagick/code/rev/54f48ab2d52a, http://www.securityfocus.com/bid/100474, https://lists.debian.org/debian-lts-announce/2018/06/msg00009.html.
5
What is the CWE ID for CVE-2017-13064?
The CWE ID for CVE-2017-13064 is 119.