CVE-2019-11005

Publication date 8 April 2019

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

9.8 · Critical

Score breakdown

Description

In GraphicsMagick 1.4 snapshot-20190322 Q8, there is a stack-based buffer overflow in the function SVGStartElement of coders/svg.c, which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a quoted font family value.

Status

Package Ubuntu Release Status
graphicsmagick 19.10 eoan
Not affected
19.04 disco Ignored end of life
18.10 cosmic Ignored end of life
18.04 LTS bionic
Fixed 1.3.28-2ubuntu0.1
16.04 LTS xenial
Not affected
14.04 LTS trusty
Not affected

Severity score breakdown

CVSS version: CVSS v3.0

Base score 9.8 · Critical

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H


Access our resources on patching vulnerabilities