CVE-2012-3438
EPSS 1.1%
Description
The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation.
How to fix CVE-2012-3438
To remediate CVE-2012-3438, upgrade the affected package to a fixed version below.
- Debian/graphicsmagick—upgrade to 1.3.16-1.1 or later
Is CVE-2012-3438 being exploited?
Low — EPSS is 1.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.3.16-1.1