CVE-2018-6799: Buffer Overflow
The AcquireCacheNexus function in magick/pixelcache.c in GraphicsMagick before 1.3.28 allows remote attackers to cause a denial of service (heap overwrite) or possibly have unspecified other impact via a crafted image file, because a pixel staging area is not used.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/graphicsmagickto a version that resolves this vulnerability.Fixed in 1.4+really1.3.35-1~deb10u2Fixed in 1.4+really1.3.35-1~deb10u3Fixed in 1.4+really1.3.36+hg16481-2+deb11u1Fixed in 1.4+really1.3.40-4Fixed in 1.4+really1.3.42-1
Event History
Frequently Asked Questions
What is CVE-2018-6799?
CVE-2018-6799 is a vulnerability in GraphicsMagick before 1.3.28 that allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted image file.
How does CVE-2018-6799 affect GraphicsMagick?
CVE-2018-6799 affects GraphicsMagick versions before 1.3.28.
What is the severity of CVE-2018-6799?
The severity of CVE-2018-6799 is rated as high with a severity value of 8.8.
How can I fix CVE-2018-6799 in GraphicsMagick?
To fix CVE-2018-6799 in GraphicsMagick, you should update to version 1.3.28 or later.
Where can I find more information about CVE-2018-6799?
More information about CVE-2018-6799 can be found at the following references: [1] [2] [3].