CVE-2019-11007: High severity GraphicsMagick Graphicsmagick vulnerability
Published Apr 8, 2019
·Updated
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a heap-based buffer over-read in the ReadMNGImage function of coders/png.c, which allows attackers to cause a denial of service or information disclosure via an image colormap.
Affected Software
9 affected componentsFixes available
GraphicsMagick Graphicsmagick<=1.3.31
openSUSE Backports SLE=15.0
openSUSE Leap=15.0
openSUSE Leap=42.3
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
Canonical Ubuntu Linux=18.04
debian/graphicsmagick
1.4+really1.3.36+hg16481-2+deb11u11.4+really1.3.40-4+deb12u11.4+really1.3.45+hg17696-11.4+really1.3.46-2
Event History
Apr 8, 2019
CVE Published
via MITRE·06:18 PM
Data Sourced
via MITRE·06:18 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:12 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·06:59 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·07:00 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this graphicsMagick vulnerability?
The vulnerability ID is CVE-2019-11007.
2
What is the severity of CVE-2019-11007?
The severity of CVE-2019-11007 is high with a score of 8.1.
3
How does CVE-2019-11007 affect GraphicsMagick?
CVE-2019-11007 allows attackers to cause a denial of service or information disclosure in GraphicsMagick.
4
Which versions of GraphicsMagick are affected by CVE-2019-11007?
Versions 1.4 snapshot-20190322 Q8, 1.4+really1.3.35-1~deb10u2, 1.4+really1.3.35-1~deb10u3, 1.4+really1.3.36+hg16481-2+deb11u1, 1.4+really1.3.40-4, and 1.4+really1.3.42-1 of GraphicsMagick are affected by CVE-2019-11007.
5
Is there a fix available for CVE-2019-11007?
Yes, the fix for CVE-2019-11007 is available in versions 1.4.0 and later of GraphicsMagick.