
Cloud Vulnerability DB
A community-led vulnerabilities database
GraphicsMagick before version 1.3.35 contains an integer overflow vulnerability and resultant heap-based buffer overflow in the HuffmanDecodeImage function located in magick/compress.c. The vulnerability was discovered in early 2020 and was assigned identifier CVE-2020-10938 (NVD, CVE).
The vulnerability has been assigned a CVSS v3.1 Base Score of 9.8 CRITICAL with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The issue stems from an integer overflow condition that leads to a heap-based buffer overflow specifically in the HuffmanDecodeImage function within the compress.c file. This vulnerability has been classified under CWE-787 (Out-of-bounds Write) and CWE-190 (Integer Overflow or Wraparound) (NVD).
The vulnerability could potentially lead to denial of service conditions or possibly allow for remote code execution when processing malformed image files (Debian Security).
The vulnerability was fixed in GraphicsMagick version 1.3.35. Various Linux distributions have released security updates to address this vulnerability: Debian released updates for stretch (1.3.30+hg15796-1~deb9u4) and buster (1.4+really1.3.35-1~deb10u1), OpenSUSE released updates for Leap 15.1 and Backports SLE-15-SP1 (Debian Security, OpenSUSE Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."