GraphicsMagick 1.3.26 has double free vulnerabilities in the ReadOneJNGImage() function in coders/png.c.
The product calls free() twice on the same memory address.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Graphicsmagick | Graphicsmagick | 1.3.26 (including) | 1.3.26 (including) |
| Graphicsmagick | Ubuntu | artful | * |
| Graphicsmagick | Ubuntu | cosmic | * |
| Graphicsmagick | Ubuntu | upstream | * |
| Graphicsmagick | Ubuntu | yakkety | * |
| Graphicsmagick | Ubuntu | zesty | * |