CVE-2012-3438

Published Aug 7, 2012

Last updated 7 years ago

Overview

Description
The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation.
Source
secalert@redhat.com
NVD status
Modified

Social media

Hype score
Not currently trending

Risk scores

CVSS 2.0

Type
Primary
Base score
4.3
Impact score
2.9
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:N/I:N/A:P

Weaknesses

nvd@nist.gov
CWE-119

Evaluator

Comment
Per: http://xforce.iss.net/xforce/xfdb/77259 'Platforms Affected: GraphicsMagick 1.3.16'
Impact
-
Solution
-

Configurations