CVE-2008-3134
EPSS 1.7%
Description
Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.
How to fix CVE-2008-3134
To remediate CVE-2008-3134, upgrade the affected package to a fixed version below.
- Debian/graphicsmagick—upgrade to 1.2.4-1 or later
- —no fix listed
Is CVE-2008-3134 being exploited?
Low — EPSS is 1.7%, meaning exploitation activity has not been observed at scale.
Affected packages (2)
- from 0, < 1.2.4-1
- from 0