Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:26856
HistorySep 21, 2020 - 6:22 a.m.

Arbitrary Code Execution

2020-09-2106:22:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
graphicsmagick
writecmykimage
heap overflow
arbitrary code execution
host os
software

EPSS

0.004

Percentile

72.5%

GraphicsMagick is vulnerable to arbitrary code execution. A heap overflow in the WriteCMYKImage() function in coders/cmyk.c during processing of multiple frames that have non-identical widths allows an attacker to execute arbitrary code on the host OS