First published: Fri Oct 27 2017(Updated: )
In ReadOneJNGImage in coders/png.c in GraphicsMagick 1.3.26, a Null Pointer Dereference occurs while transferring JPEG scanlines, related to a PixelPacket pointer.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Graphicsmagick Graphicsmagick | =1.3.26 | |
Debian Debian Linux | =8.0 | |
Debian Debian Linux | =9.0 | |
debian/graphicsmagick | 1.4+really1.3.36+hg16481-2+deb11u1 1.4+really1.3.40-4 1.4+really1.3.45-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-15930 is a vulnerability in GraphicsMagick 1.3.26 that causes a Null Pointer Dereference while transferring JPEG scanlines.
CVE-2017-15930 has a severity score of 8.8 (high).
GraphicsMagick 1.3.26 is affected by CVE-2017-15930.
To fix CVE-2017-15930, update GraphicsMagick to a version that is not vulnerable.
More information about CVE-2017-15930 can be found at the following references: - http://hg.graphicsmagick.org/hg/GraphicsMagick?cmd=changeset;node=6fc54b6d2be8 - http://hg.graphicsmagick.org/hg/GraphicsMagick?cmd=changeset;node=da135eaedc3b - https://sourceforge.net/p/graphicsmagick/bugs/518/