CRITICAL
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c
Published Dec 24, 2019
9.8
CRITICALCVSS 3.1
EPSS 2.71%
Description
In GraphicsMagick 1.4 snapshot-20190403 Q8, there is a use-after-free in ThrowException and ThrowLoggedException of magick/error.c.
Affected products
No data.
Configuration 1
- 1.4
Configuration 2
OR
- 8.0
- 9.0
- 10.0
- sle-15
- 15.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/44ab7f6c20b4 x_refsource_MISCMailing ListPatchVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00026.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00064.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2020/01/msg00029.html mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- https://sourceforge.net/p/graphicsmagick/bugs/603/ x_refsource_MISCExploitIssue TrackingThird Party Advisory
- https://www.debian.org/security/2020/dsa-4640 vendor-advisoryx_refsource_DEBIANThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://hg.graphicsmagick.org/hg/GraphicsMagick/rev/44ab7f6c20b4 | x_refsource_MISCMailing ListPatchVendor Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00026.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2020-01/msg00064.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://lists.debian.org/debian-lts-announce/2020/01/msg00029.html | mailing-listx_refsource_MLISTMailing ListThird Party Advisory | |
| https://sourceforge.net/p/graphicsmagick/bugs/603/ | x_refsource_MISCExploitIssue TrackingThird Party Advisory | |
| https://www.debian.org/security/2020/dsa-4640 | vendor-advisoryx_refsource_DEBIANThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Dec 24, 2019
Updated Aug 5, 2024
Reserved Dec 24, 2019
Link CVE-2019-19950
CISA Vulnrichment
Updated n/a