ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.
References
| Link | Resource |
|---|---|
| http://www.graphicsmagick.org/NEWS.html | Release Notes |
| https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/883ebf8cae6dfa5873d975fe3476b1a188ef3f9f | Patch |
| https://sourceforge.net/p/graphicsmagick/bugs/750/ | Permissions Required |
Configurations
History
No history.
Information
Published : 2025-03-07 06:15
Updated : 2026-01-29 20:56
NVD link : CVE-2025-27796
Mitre link : CVE-2025-27796
CVE.ORG link : CVE-2025-27796
JSON object : View
Products Affected
graphicsmagick
- graphicsmagick
CWE
CWE-908
Use of Uninitialized Resource
