CVE-2017-14042

medium

Description

A memory allocation failure was discovered in the ReadPNMImage function in coders/pnm.c in GraphicsMagick 1.3.26. The vulnerability causes a big memory allocation, which may lead to remote denial of service in the MagickRealloc function in magick/memory.c.

References

https://usn.ubuntu.com/4206-1/

http://www.securityfocus.com/bid/100556

http://hg.code.sf.net/p/graphicsmagick/code/rev/3bbf7a13643d

Details

Source: Mitre, NVD

Published: 2017-08-30

Updated: 2019-12-03

Risk Information

CVSS v2

Base Score: 4.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Severity: Medium