PublicDateAtUSN: 2017-07-02 22:29:00 UTC Candidate: CVE-2017-10794 PublicDate: 2017-07-02 22:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-10794 http://hg.code.sf.net/p/graphicsmagick/code/rev/a20bee0a0ad2 https://sourceforge.net/p/graphicsmagick/code/ci/a20bee0a0ad216aa11a2be3de63b60ca6bef4106/ https://ubuntu.com/security/notices/USN-4206-1 Description: When GraphicsMagick 1.3.25 processes an RGB TIFF picture (with metadata indicating a single sample per pixel) in coders/tiff.c, a buffer overflow occurs, related to QuantumTransferMode. Ubuntu-Description: Notes: Bugs: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=867085 Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_graphicsmagick: upstream_graphicsmagick: needs-triage precise/esm_graphicsmagick: DNE trusty_graphicsmagick: ignored (out of standard support) trusty/esm_graphicsmagick: not-affected (code not present) vivid/ubuntu-core_graphicsmagick: DNE xenial_graphicsmagick: released (1.3.23-1ubuntu0.2) yakkety_graphicsmagick: ignored (reached end-of-life) zesty_graphicsmagick: ignored (reached end-of-life) artful_graphicsmagick: ignored (reached end-of-life) bionic_graphicsmagick: not-affected (1.3.26-1) cosmic_graphicsmagick: not-affected (1.3.26-1) disco_graphicsmagick: not-affected (1.3.26-1) eoan_graphicsmagick: not-affected (1.3.26-1) devel_graphicsmagick: not-affected (1.3.26-1)