Lucene search

K
osvGoogleOSV:DLA-547-1
HistoryJul 11, 2016 - 12:00 a.m.

graphicsmagick - security update

2016-07-1100:00:00
Google
osv.dev
12

0.015 Low

EPSS

Percentile

86.8%

It was discovered that there were two denial of service vulnerabilities
in graphicsmagick, a collection of image processing tools:

  • CVE-2016-5240
    Prevent denial-of-service by detecting and rejecting
    negative stroke-dasharray arguments which were resulting in an
    endless loop.
  • CVE-2016-5241
    Fix divide-by-zero problem if fill or stroke pattern
    image has zero columns or rows to prevent DoS attack.

For Debian 7 Wheezy, this issue has been fixed in graphicsmagick version
1.3.16-1.1+deb7u3.

We recommend that you upgrade your graphicsmagick packages.