Vulnerability Name: CVE-2008-3134 (CCN-43511) Assigned: 2008-06-29 Published: 2008-06-29 Updated: 2017-08-08 Summary: Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): Access Complexity (AC): Authentication (Au): Impact Metrics: Confidentiality (C): Integrity (I): Availibility (A):
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P )3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): Access Complexity (AC): Athentication (Au): Impact Metrics: Confidentiality (C): Integrity (I): Availibility (A):
Vulnerability Type: CWE-399 Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2008-3134 Source: SUSE Type: UNKNOWNSUSE-SR:2008:020 Source: CCN Type: SA30879GraphicsMagick Multiple Denial of Service Vulnerabilities Source: SECUNIA Type: Vendor Advisory30879 Source: SECUNIA Type: UNKNOWN32151 Source: CCN Type: SECTRACK ID: 1020413GraphicsMagick Bugs in Multiple Readers Lets Remote Users Deny Service Source: CONFIRM Type: UNKNOWNhttp://sourceforge.net/forum/forum.php?forum_id=841176 Source: CCN Type: SourceForge.net: FilesGraphicsMagick, File Release Notes and Changelog, Release Name: 1.2.4 Source: CONFIRM Type: UNKNOWNhttp://sourceforge.net/project/shownotes.php?release_id=610253 Source: DEBIAN Type: DSA-1903graphicsmagick -- several vulnerabilities Source: BID Type: UNKNOWN30055 Source: CCN Type: BID-30055GraphicsMagick Multiple Denial Of Service Vulnerabilities Source: SECTRACK Type: UNKNOWN1020413 Source: VUPEN Type: UNKNOWNADV-2008-1984 Source: XF Type: UNKNOWNgraphicsmagick-multiple-dos(43511) Source: XF Type: UNKNOWNgraphicsmagick-multiple-dos(43511) Source: XF Type: UNKNOWNgraphicsmagick-getimagecharacteristics-dos(43513) Source: SUSE Type: SUSE-SR:2008:020SUSE Security Summary Report Vulnerable Configuration: Configuration 1 :cpe:/a:graphicsmagick:graphicsmagick:1.0:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.0.4:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.0.6:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.3:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.4:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.5:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.6:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.8:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.9:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.10:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.11:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.12:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.2:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.2.18:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:graphicsmagick:graphicsmagick:1.1.10:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.11:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.0:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.0.4:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.0.6:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.12:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.3:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.4:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.5:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.6:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.8:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.1.9:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.2:*:*:*:*:*:*:* OR cpe:/a:graphicsmagick:graphicsmagick:1.2.18:*:*:*:*:*:*:* AND cpe:/o:debian:debian_linux:4.0:*:*:*:*:*:*:* OR cpe:/o:debian:debian_linux:5.0:*:*:*:*:*:*:* Denotes that component is vulnerableVulnerability Name: CVE-2008-3134 (CCN-43513) Assigned: 2008-06-29 Published: 2008-06-29 Updated: 2017-08-08 Summary: Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file. CVSS v3 Severity: 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): NetworkAttack Complexity (AC): LowPrivileges Required (PR): NoneUser Interaction (UI): NoneScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
CVSS v2 Severity: 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P )3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): Access Complexity (AC): Authentication (Au): Impact Metrics: Confidentiality (C): Integrity (I): Availibility (A):
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P )3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): Access Complexity (AC): Athentication (Au): Impact Metrics: Confidentiality (C): Integrity (I): Availibility (A):
Vulnerability Type: CWE-399 Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2008-3134 Source: CCN Type: SA30879GraphicsMagick Multiple Denial of Service Vulnerabilities Source: CCN Type: SECTRACK ID: 1020413GraphicsMagick Bugs in Multiple Readers Lets Remote Users Deny Service Source: CCN Type: SourceForge.net: FilesGraphicsMagick, File Release Notes and Changelog, Release Name: 1.2.4 Source: DEBIAN Type: DSA-1903graphicsmagick -- several vulnerabilities Source: CCN Type: BID-30055GraphicsMagick Multiple Denial Of Service Vulnerabilities Source: XF Type: UNKNOWNgraphicsmagick-getimagecharacteristics-dos(43513) Source: SUSE Type: SUSE-SR:2008:020SUSE Security Summary Report Oval Definitions BACK
graphicsmagick graphicsmagick 1.0
graphicsmagick graphicsmagick 1.0.4
graphicsmagick graphicsmagick 1.0.6
graphicsmagick graphicsmagick 1.1
graphicsmagick graphicsmagick 1.1.3
graphicsmagick graphicsmagick 1.1.4
graphicsmagick graphicsmagick 1.1.5
graphicsmagick graphicsmagick 1.1.6
graphicsmagick graphicsmagick 1.1.8
graphicsmagick graphicsmagick 1.1.9
graphicsmagick graphicsmagick 1.1.10
graphicsmagick graphicsmagick 1.1.11
graphicsmagick graphicsmagick 1.1.12
graphicsmagick graphicsmagick 1.2
graphicsmagick graphicsmagick 1.2.18
graphicsmagick graphicsmagick 1.1.10
graphicsmagick graphicsmagick 1.1.11
graphicsmagick graphicsmagick 1.1
graphicsmagick graphicsmagick 1.0
graphicsmagick graphicsmagick 1.0.4
graphicsmagick graphicsmagick 1.0.6
graphicsmagick graphicsmagick 1.1.12
graphicsmagick graphicsmagick 1.1.3
graphicsmagick graphicsmagick 1.1.4
graphicsmagick graphicsmagick 1.1.5
graphicsmagick graphicsmagick 1.1.6
graphicsmagick graphicsmagick 1.1.8
graphicsmagick graphicsmagick 1.1.9
graphicsmagick graphicsmagick 1.2
graphicsmagick graphicsmagick 1.2.18
debian debian linux 4.0
debian debian linux 5.0