Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in magick/utility.c, and (3) GetTransformTokens function in coders/svg.c.
2017-02-03T15:59:00.150
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 5.5 (MEDIUM)
AV:N/AC:M/Au:N/C:N/I:N/A:P
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | graphicsmagick | graphicsmagick | 1.3.23 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Application | suse | linux_enterprise_debuginfo | 11 | Yes |
Application | suse | studio_onsite | 1.3 | Yes |
Operating System | opensuse | leap | 42.1 | Yes |
Operating System | opensuse | opensuse | 13.2 | Yes |
Operating System | suse | linux_enterprise_software_development_kit | 11 | Yes |