In GraphicsMagick 1.3.28, there is a divide-by-zero in the ReadMNGImage function of coders/png.c. Remote attackers could leverage this vulnerability to cause a crash and denial of service via a crafted mng file.
CPE | Name | Operator | Version |
---|---|---|---|
debian_linux | eq | 8.0 | |
debian_linux | eq | 7.0 | |
debian_linux | eq | 9.0 | |
graphicsmagick | eq | 1.3.28 |
www.securityfocus.com/bid/103526
lists.debian.org/debian-lts-announce/2018/03/msg00025.html
lists.debian.org/debian-lts-announce/2018/08/msg00002.html
lists.fedoraproject.org/archives/list/[email protected]/message/3IYH7QSNXXOIDFTYLY455ANZ3JWQ7FCS/
lists.fedoraproject.org/archives/list/[email protected]/message/FS76VNCFL3FVRMGXQEMHBOKA7EE46BTS/
sourceforge.net/p/graphicsmagick/bugs/554/
www.debian.org/security/2018/dsa-4321