Vulnerability Name:

CVE-2012-3438 (CCN-77259)

Assigned:2012-07-30
Published:2012-07-30
Updated:2017-08-29
Summary:The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation.
Per: http://xforce.iss.net/xforce/xfdb/77259

'Platforms Affected: GraphicsMagick 1.3.16'

CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
4.3 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
3.2 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-119
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2012-3438

Source: CCN
Type: GraphicsMagick Mercurial Repository
coders/png.c: Some typecasts were inconsistent with libpng-1.4 and later.

Source: CONFIRM
Type: Exploit, Patch
http://graphicsmagick.hg.sourceforge.net/hgweb/graphicsmagick/graphicsmagick/rev/d6e469d02cd2

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2013:0536

Source: CCN
Type: SA50090
GraphicsMagick PNG Image Parsing Denial of Service Vulnerability

Source: SECUNIA
Type: Vendor Advisory
50090

Source: CCN
Type: GraphicsMagick Web site
GraphicsMagick News

Source: MANDRIVA
Type: UNKNOWN
MDVSA-2012:165

Source: CCN
Type: OSVDB ID: 84323
GraphicsMagick PNG Image Handling Casting Error DoS

Source: BID
Type: UNKNOWN
54716

Source: CCN
Type: BID-54716
GraphicsMagick 'png_IM_malloc()' Function Denial of Service Vulnerability

Source: CCN
Type: Red Hat Bugzilla Bug 844105
CVE-2012-3438 GraphicsMagick: png_IM_malloc() size argument

Source: MISC
Type: Patch
https://bugzilla.redhat.com/show_bug.cgi?id=844105

Source: XF
Type: UNKNOWN
graphicsmagick-png-dos(77259)

Source: XF
Type: UNKNOWN
graphicsmagick-png-dos(77259)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:graphicsmagick:graphicsmagick:1.3.16:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:graphicsmagick:graphicsmagick:1.3.16:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20123438
    V
    CVE-2012-3438
    2022-06-30
    oval:org.opensuse.security:def:26222
    P
    Security update for virglrenderer (Important) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:111888
    P
    GraphicsMagick-1.3.25-1.1 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:26221
    P
    Security update for python-numpy (Moderate) (in QA)
    2022-01-17
    oval:org.opensuse.security:def:33760
    P
    Security update for mariadb (Moderate)
    2021-12-30
    oval:org.opensuse.security:def:26158
    P
    Security update for binutils (Moderate)
    2021-11-02
    oval:org.opensuse.security:def:57117
    P
    Security update for opensc (Important)
    2021-10-29
    oval:org.opensuse.security:def:26147
    P
    Security update for MozillaFirefox (Important)
    2021-10-15
    oval:org.opensuse.security:def:26145
    P
    Security update for the Linux Kernel (Important)
    2021-10-12
    oval:org.opensuse.security:def:105467
    P
    GraphicsMagick-1.3.25-1.1 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:33004
    P
    Security update for transfig (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:29422
    P
    Security update for gtk-vnc (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:32993
    P
    Security update for libesmtp (Important)
    2021-09-02
    oval:org.opensuse.security:def:32992
    P
    Security update for gstreamer-plugins-good (Moderate)
    2021-09-02
    oval:org.opensuse.security:def:34506
    P
    Security update for MozillaFirefox (Important)
    2021-08-17
    oval:org.opensuse.security:def:34466
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-15
    oval:org.opensuse.security:def:33672
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-15
    oval:org.opensuse.security:def:36358
    P
    GraphicsMagick-1.2.5-4.33.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:57191
    P
    Security update for openssl (Moderate)
    2021-03-24
    oval:org.opensuse.security:def:33083
    P
    Security update for avahi (Moderate)
    2021-02-23
    oval:org.opensuse.security:def:26192
    P
    Security update for php72 (Important)
    2021-02-17
    oval:org.opensuse.security:def:55841
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:26157
    P
    Security update for the Linux Kernel (Important)
    2021-02-09
    oval:org.opensuse.security:def:26146
    P
    Security update for python3 (Important)
    2021-02-08
    oval:org.opensuse.security:def:26111
    P
    Security update for cups (Moderate)
    2021-02-02
    oval:org.opensuse.security:def:33784
    P
    Security update for MozillaFirefox (Important)
    2021-01-12
    oval:org.opensuse.security:def:33721
    P
    Security update for java-1_8_0-ibm (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:25983
    P
    Security update for openexr (Moderate)
    2020-12-23
    oval:org.opensuse.security:def:33615
    P
    Security update for python3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:54997
    P
    python-requests on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26864
    P
    apache2-mod_perl on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25908
    P
    Security update for flash-player (Important)
    2020-12-01
    oval:org.opensuse.security:def:54891
    P
    libmpfr4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26825
    P
    sysconfig on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25907
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:54718
    P
    MozillaFirefox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26776
    P
    libzip1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33828
    P
    Security update for gnuplot (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54480
    P
    gnome-keyring on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26723
    P
    kde4-kgreeter-plugins on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54340
    P
    opensc on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26572
    P
    kdelibs4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54318
    P
    libtag1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26488
    P
    Security update for cacti, cacti-spine (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28528
    P
    Security update for ImageMagick
    2020-12-01
    oval:org.opensuse.security:def:28982
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26431
    P
    Security update for tor (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28493
    P
    Security update for curl
    2020-12-01
    oval:org.opensuse.security:def:26350
    P
    Security update for ansible (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27855
    P
    Security update for popt
    2020-12-01
    oval:org.opensuse.security:def:33458
    P
    Security update for iSCSI
    2020-12-01
    oval:org.opensuse.security:def:27811
    P
    Security update for LibreOffice
    2020-12-01
    oval:org.opensuse.security:def:33370
    P
    Security update for wget (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27797
    P
    Security update for lzo
    2020-12-01
    oval:org.opensuse.security:def:33313
    P
    libsnmp15-openssl1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27758
    P
    Security update for gnutls
    2020-12-01
    oval:org.opensuse.security:def:27356
    P
    GraphicsMagick on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33218
    P
    openssh on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27709
    P
    Security update for bash
    2020-12-01
    oval:org.opensuse.security:def:27321
    P
    wpa_supplicant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27656
    P
    Security update for python-httplib2
    2020-12-01
    oval:org.opensuse.security:def:26683
    P
    dbus-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27505
    P
    libxine-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26639
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27421
    P
    inkscape on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26625
    P
    pam_ldap on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30454
    P
    Security update for ImageMagick
    2020-12-01
    oval:org.opensuse.security:def:54317
    P
    libssh4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27364
    P
    PolicyKit-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26586
    P
    libexiv2-4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30417
    P
    Security update for xorg-x11-libXfixes
    2020-12-01
    oval:org.opensuse.security:def:27282
    P
    qt3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26537
    P
    dhcp on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29779
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27154
    P
    kbd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26484
    P
    Security update for chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:29735
    P
    Security update for freeradius-server (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27090
    P
    bash on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26333
    P
    Security update for redis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29717
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:27079
    P
    ant on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26249
    P
    Security update for libtomcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29678
    P
    Security update for e2fsprogs
    2020-12-01
    oval:org.opensuse.security:def:27594
    P
    Security update for GraphicsMagick
    2020-12-01
    oval:org.opensuse.security:def:29629
    P
    Security update for clamav
    2020-12-01
    oval:org.opensuse.security:def:27559
    P
    rubygem-i18n-0_6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29575
    P
    Security update for apache2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26921
    P
    java-1_6_0-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26877
    P
    cups on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25919
    P
    Security update for libplist (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29337
    P
    Security update for spacewalk
    2020-12-01
    oval:org.opensuse.security:def:26863
    P
    apache2-mod_jk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29280
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26824
    P
    sudo on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29194
    P
    Security update for openldap2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26775
    P
    libxslt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29063
    P
    Security update for bzip2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26722
    P
    kbd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55760
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28994
    P
    Security update for conntrack-tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26571
    P
    kdelibs3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55722
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28983
    P
    Security update for vorbis-tools (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26487
    P
    Security update for redis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55648
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27595
    P
    Security update for ImageMagick
    2020-12-01
    oval:org.opensuse.security:def:27078
    P
    amavisd-new on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26430
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55556
    P
    Security update for python (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27560
    P
    rubygem-json_pure on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26349
    P
    Security update for redis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55448
    P
    Security update for wget (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26922
    P
    java-1_7_0-ibm on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55163
    P
    lhasa on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26878
    P
    curl on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:25972
    P
    SUSE-SU-2013:0757-1 -- Security update for ImageMagick
    2014-09-08
    oval:org.mitre.oval:def:25925
    P
    SUSE-SU-2013:0756-1 -- Security update for ImageMagick
    2014-09-08
    oval:org.opensuse.security:def:79825
    P
    Security update for ImageMagick
    2013-03-20
    oval:com.ubuntu.precise:def:20123438000
    V
    CVE-2012-3438 on Ubuntu 12.04 LTS (precise) - medium.
    2012-08-07
    oval:com.ubuntu.trusty:def:20123438000
    V
    CVE-2012-3438 on Ubuntu 14.04 LTS (trusty) - medium.
    2012-08-07
    oval:com.ubuntu.xenial:def:20123438000
    V
    CVE-2012-3438 on Ubuntu 16.04 LTS (xenial) - medium.
    2012-08-07
    oval:com.ubuntu.xenial:def:201234380000000
    V
    CVE-2012-3438 on Ubuntu 16.04 LTS (xenial) - medium.
    2012-08-07
    BACK
    graphicsmagick graphicsmagick 1.3.16
    graphicsmagick graphicsmagick 1.3.16