CVE-2016-2317
Summary
| CVE | CVE-2016-2317 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-02-03 15:59:00 UTC |
| Updated | 2018-10-30 16:27:00 UTC |
| Description | Multiple buffer overflows in GraphicsMagick 1.3.23 allow remote attackers to cause a denial of service (crash) via a crafted SVG file, related to the (1) TracePoint function in magick/render.c, (2) GetToken function in magick/utility.c, and (3) GetTransformTokens function in coders/svg.c. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Debian -- Security Information -- DSA-3746-1 graphicsmagick |
DEBIAN |
www.debian.org |
Third Party Advisory |
| oss-security - Re: Security issues addressed in GraphicsMagick SVG
reader |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| oss-security - Re: CVE requests: Multiple vulnerabilities in GraphicsMagick parsing and processing SVG files |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| oss-security - GraphicsMagick 1.3.25 fixes some security issues |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| GraphicsMagick Multiple Security Vulnerabilities |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| oss-security - Re: ImageMagick Is On Fire -- CVE-2016-3714 |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| [security-announce] openSUSE-SU-2016:1724-1: important: Security update |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| Bug 1306148 – CVE-2016-2317 CVE-2016-2318 GraphicsMagick: SVG parsing issues |
CONFIRM |
bugzilla.redhat.com |
Issue Tracking |
| [security-announce] openSUSE-SU-2016:2073-1: important: Security update |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| oss-security - Re: GraphicsMagick 1.3.25 fixes some security issues |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| [security-announce] SUSE-SU-2016:1783-1: important: Security update for |
SUSE |
lists.opensuse.org |
Third Party Advisory |
| oss-security - Security issues addressed in GraphicsMagick SVG reader |
MLIST |
www.openwall.com |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 500989 Alpine Linux Security Update for graphicsmagick
- 690627 Free Berkeley Software Distribution (FreeBSD) Security Update for graphicsmagick (e714b7d2-39f6-4992-9f48-e6b2f5f949df)