CVE-2019-11010: Medium severity GraphicsMagick Graphicsmagick vulnerability
Published Apr 8, 2019
·Updated
In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.
Affected Software
5 affected componentsFixes available
GraphicsMagick Graphicsmagick<=1.3.31
Debian Debian Linux=8.0
openSUSE Leap=15.0
openSUSE Leap=42.3
debian/graphicsmagick
1.4+really1.3.36+hg16481-2+deb11u11.4+really1.3.40-4+deb12u11.4+really1.3.45+hg17696-11.4+really1.3.46-2
Remediation
Patch Available
Event History
Apr 8, 2019
CVE Published
via MITRE·06:18 PM
Data Sourced
via MITRE·06:18 PM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:12 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·06:59 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·07:00 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is the vulnerability ID of this GraphicsMagick vulnerability?
The vulnerability ID is CVE-2019-11010.
2
What is the severity of CVE-2019-11010?
The severity of CVE-2019-11010 is medium with a CVSS score of 6.5.
3
What is the affected software?
The affected software includes GraphicsMagick versions 1.4 snapshot-20190322 Q8, Debian Linux 8.0, openSUSE Leap 15.0, and openSUSE Leap 42.3.
4
How does CVE-2019-11010 impact the software?
CVE-2019-11010 allows attackers to cause a denial of service via a crafted image file.
5
How can I fix the vulnerability?
To fix CVE-2019-11010, update to the patched versions of GraphicsMagick, such as 1.4+really1.3.35-1~deb10u2, 1.4+really1.3.35-1~deb10u3, 1.4+really1.3.36+hg16481-2+deb11u1, 1.4+really1.3.40-4, or 1.4+really1.3.42-1.