Critical severity9.1NVD Advisory· Published Dec 24, 2019· Updated Jun 17, 2026
CVE-2019-19953
CVE-2019-19953
Description
In GraphicsMagick 1.4 snapshot-20191208 Q8, there is a heap-based buffer over-read in the function EncodeImage of coders/pict.c.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- GraphicsMagick/GraphicsMagickdescription
- Range: 1.4 snapshot-20191208 Q8
- osv-coords2 versionspkg:rpm/opensuse/GraphicsMagick&distro=openSUSE%20Leap%2015.1pkg:rpm/suse/GraphicsMagick&distro=SUSE%20Package%20Hub%2015%20SP1
< 1.3.29-lp151.4.14.1+ 1 more
- (no CPE)range: < 1.3.29-lp151.4.14.1
- (no CPE)range: < 1.3.29-bp151.5.9.1
Patches
Vulnerability mechanics
References
6- hg.graphicsmagick.org/hg/GraphicsMagick/rev/28f8bacd4bbfnvdMailing ListPatchVendor Advisory
- sourceforge.net/p/graphicsmagick/bugs/617/nvdExploitIssue TrackingThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-01/msg00026.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-01/msg00064.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2020/01/msg00029.htmlnvdMailing ListThird Party Advisory
- www.debian.org/security/2020/dsa-4640nvdThird Party Advisory
News mentions
0No linked articles in our index yet.