CVE-2019-19953: Critical severity imagemagick vulnerability
Published Dec 24, 2019
·Updated
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
Affected Software
7 affected componentsFixes available
debian/graphicsmagick
1.4+really1.3.36+hg16481-2+deb11u11.4+really1.3.40-41.4+really1.3.45+hg17689-1
GraphicsMagick Graphicsmagick=1.4-2019-12-08
Debian Debian Linux=8.0
Debian Debian Linux=9.0
Debian Debian Linux=10.0
openSUSE Backports=sle-15-sp1
openSUSE Leap=15.1
Remediation
Event History
Dec 24, 2019
CVE Published
via MITRE·12:06 AM
Data Sourced
via MITRE·12:06 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·11:25 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:19 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2019-19953?
CVE-2019-19953 is a heap-based buffer over-read vulnerability in GraphicsMagick.
2
How severe is CVE-2019-19953?
CVE-2019-19953 has a severity rating of 9.1 (Critical).
3
What software versions are affected by CVE-2019-19953?
GraphicsMagick versions 1.4 snapshot-20191208 Q8 are affected by CVE-2019-19953.
4
How can I fix CVE-2019-19953?
To fix CVE-2019-19953, update GraphicsMagick to version 1.4+ or apply the specific patches provided by the vendor.
5
Where can I find more information about CVE-2019-19953?
For more information about CVE-2019-19953, you can refer to the following references: http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/28f8bacd4bbf, https://sourceforge.net/p/graphicsmagick/bugs/617/, and https://security-tracker.debian.org/tracker/CVE-2019-19953.