CVE-2008-3134
Summary
| CVE | CVE-2008-3134 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2008-07-10 23:41:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
NoneAvailability
PartialAV:N/AC:L/Au:N/C:N/I:N/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Graphicsmagick | Graphicsmagick | 1.0 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.0.4 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.0.6 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.1 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.1.10 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.1.11 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.1.12 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.1.3 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.1.4 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.1.5 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.1.6 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.1.8 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.1.9 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.2 | All | All | All |
| Application | Graphicsmagick | Graphicsmagick | 1.2.18 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GraphicsMagick Multiple Denial Of Service Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| GraphicsMagick Bugs in Multiple Readers Lets Remote Users Deny Service - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| Webmail - OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| GraphicsMagick Multiple Denial of Service Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Page not found - SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| [security-announce] SUSE Security Summary Report: SUSE-SR:2008:020 | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| SUSE update for dovecot and graphicsmagic - Secunia Advisories - Vulnerability Intelligence - Secunia.com | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| GraphicsMagick | Free Audio & Video software downloads at SourceForge.net | af854a3a-2127-422b-91ae-364da2661108 | sourceforge.net | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
| Organization | Published | Contributor | Statement |
|---|---|---|---|
| Red Hat | 2010-05-14 | Mark J Cox | Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2008-3134 |
There are currently no legacy QID mappings associated with this CVE.