CVE-2019-11506: Buffer Overflow
In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in magick/export.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2019-11506.
What is the severity rating of CVE-2019-11506?
The severity rating of CVE-2019-11506 is 8.8 (high).
Which software versions are affected by CVE-2019-11506?
GraphicsMagick versions 1.3.30 to 1.4 snapshot-20190403 Q8 are affected by CVE-2019-11506.
What is the impact of CVE-2019-11506?
CVE-2019-11506 can cause a denial of service or possibly have unspecified other impact via a crafted image file.
Is there a fix available for CVE-2019-11506?
Yes, there are fix versions available for CVE-2019-11506: 1.4+really1.3.35-1~deb10u2, 1.4+really1.3.35-1~deb10u3, 1.4+really1.3.36+hg16481-2+deb11u1, 1.4+really1.3.40-4, and 1.4+really1.3.42-1.