CVE Vulnerabilities

CVE-2019-11474

Incorrect Calculation

Published: Apr 23, 2019 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
LOW

coders/xwd.c in GraphicsMagick 1.3.31 allows attackers to cause a denial of service (floating-point exception and application crash) by crafting an XWD image file, a different vulnerability than CVE-2019-11008 and CVE-2019-11009.

Weakness

The product performs a calculation that generates incorrect or unintended results that are later used in security-critical decisions or resource management.

Affected Software

Name Vendor Start Version End Version
Graphicsmagick Graphicsmagick 1.3.31 (including) 1.3.31 (including)
Graphicsmagick Ubuntu bionic *
Graphicsmagick Ubuntu cosmic *
Graphicsmagick Ubuntu disco *
Graphicsmagick Ubuntu esm-apps/xenial *
Graphicsmagick Ubuntu esm-infra-legacy/trusty *
Graphicsmagick Ubuntu trusty *
Graphicsmagick Ubuntu trusty/esm *
Graphicsmagick Ubuntu upstream *
Graphicsmagick Ubuntu xenial *

Potential Mitigations

  • Use languages, libraries, or frameworks that make it easier to handle numbers without unexpected consequences.
  • Examples include safe integer handling packages such as SafeInt (C++) or IntegerLib (C or C++).
  • Use languages, libraries, or frameworks that make it easier to handle numbers without unexpected consequences.
  • Examples include safe integer handling packages such as SafeInt (C++) or IntegerLib (C or C++).

References