Medium severity6.5NVD Advisory· Published Mar 18, 2020· Updated Jun 17, 2026
CVE-2019-12921
CVE-2019-12921
Description
In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- GraphicsMagick/GraphicsMagickdescription
- Range: <1.3.32
- osv-coords2 versionspkg:rpm/opensuse/GraphicsMagick&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/GraphicsMagick&distro=SUSE%20Package%20Hub%2015%20SP1
< 1.3.29-lp151.4.17.1+ 1 more
- (no CPE)range: < 1.3.29-lp151.4.17.1
- (no CPE)range: < 1.3.29-bp151.5.12.1
Patches
Vulnerability mechanics
References
6- lists.opensuse.org/opensuse-security-announce/2020-03/msg00049.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-03/msg00051.htmlnvdMailing ListThird Party Advisory
- www.graphicsmagick.orgnvdProductVendor Advisory
- github.com/d0ge/data-processing/blob/master/CVE-2019-12921.mdnvdThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/03/msg00026.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2020/dsa-4675nvdThird Party Advisory
News mentions
0No linked articles in our index yet.