CVE-2019-19951: Buffer Overflow
In GraphicsMagick 1.4 snapshot-20190423 Q8, there is a heap-based buffer overflow in the function ImportRLEPixels of coders/miff.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-19951?
The severity of CVE-2019-19951 is critical with a CVSS score of 9.8.
What is the affected software for CVE-2019-19951?
The affected software for CVE-2019-19951 includes GraphicsMagick 1.4 snapshot-20190423 Q8 and various versions of Debian and openSUSE.
How can I fix CVE-2019-19951 on Debian Linux?
To fix CVE-2019-19951 on Debian Linux, you can update the graphicsmagick package to versions 1.4+really1.3.35-1~deb10u2, 1.4+really1.3.35-1~deb10u3, 1.4+really1.3.36+hg16481-2+deb11u1, 1.4+really1.3.40-4, or 1.4+really1.3.42-1.
What is the CWE ID for CVE-2019-19951?
The CWE ID for CVE-2019-19951 is CWE-119 and CWE-787.
Where can I find more information about CVE-2019-19951?
You can find more information about CVE-2019-19951 at the following references: [1] http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/bc99af93614d [2] http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00026.html [3] http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00064.html