CVE-2017-18230: Null Pointer Dereference
An issue was discovered in GraphicsMagick 1.3.26. A NULL pointer dereference vulnerability was found in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue in GraphicsMagick?
The vulnerability ID for this issue in GraphicsMagick is CVE-2017-18230.
What is the severity of CVE-2017-18230?
The severity of CVE-2017-18230 is medium.
How does the vulnerability CVE-2017-18230 affect GraphicsMagick?
The vulnerability CVE-2017-18230 affects GraphicsMagick by causing a NULL pointer dereference vulnerability in the function ReadCINEONImage in coders/cineon.c, which allows attackers to cause a denial of service via a crafted file.
Which versions of GraphicsMagick are affected by the vulnerability CVE-2017-18230?
The versions of GraphicsMagick affected by the vulnerability CVE-2017-18230 are 1.3.26.
How can I fix the vulnerability CVE-2017-18230 in GraphicsMagick?
To fix the vulnerability CVE-2017-18230 in GraphicsMagick, you should update to the following versions: 1.4+really1.3.35-1~deb10u2, 1.4+really1.3.35-1~deb10u3, 1.4+really1.3.36+hg16481-2+deb11u1, 1.4+really1.3.40-4, or 1.4+really1.3.42-1.