In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a memory leak in the function ReadMPCImage of coders/mpc.c, which allows attackers to cause a denial of service via a crafted image file.
The product does not sufficiently track and release allocated memory after it has been used, which slowly consumes remaining memory.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Graphicsmagick | Graphicsmagick | * | 1.3.31 (including) |
Graphicsmagick | Ubuntu | bionic | * |
Graphicsmagick | Ubuntu | cosmic | * |
Graphicsmagick | Ubuntu | disco | * |
Graphicsmagick | Ubuntu | esm-apps/xenial | * |
Graphicsmagick | Ubuntu | esm-infra-legacy/trusty | * |
Graphicsmagick | Ubuntu | trusty | * |
Graphicsmagick | Ubuntu | trusty/esm | * |
Graphicsmagick | Ubuntu | xenial | * |