Back

MEDIUM

GraphicsMagick: memory information disclosure in DescribeImage function in magick/describe.c

Published Nov 1, 2017

Description

GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function of the magick/describe.c file, because of a heap-based buffer over-read. The portion of the code containing the vulnerability is responsible for printing the IPTC Profile information contained in the image. This vulnerability can be triggered with a specially crafted MIFF file. There is an out-of-bounds buffer dereference because certain increments are never checked.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 1, 2017
Updated Aug 5, 2024
Reserved Nov 1, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Nov 1, 2017