Unrated severityNVD Advisory· Published Aug 7, 2012· Updated Apr 29, 2026
CVE-2012-3438
CVE-2012-3438
Description
The Magick_png_malloc function in coders/png.c in GraphicsMagick 6.7.8-6 does not use the proper variable type for the allocation size, which might allow remote attackers to cause a denial of service (crash) via a crafted PNG file that triggers incorrect memory allocation.
Affected products
1- cpe:2.3:a:graphicsmagick:graphicsmagick:1.3.16:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- bugzilla.redhat.com/show_bug.cginvdPatch
- graphicsmagick.hg.sourceforge.net/hgweb/graphicsmagick/graphicsmagick/rev/d6e469d02cd2nvdExploitPatch
- secunia.com/advisories/50090nvdVendor Advisory
- lists.opensuse.org/opensuse-updates/2013-03/msg00102.htmlnvd
- www.mandriva.com/security/advisoriesnvd
- www.securityfocus.com/bid/54716nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/77259nvd
News mentions
0No linked articles in our index yet.