CVE-2008-3134
Last modified
CVE-2008-3134 is a vulnerability of currently unknown severity. Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.. EPSS estimates a 2.13% chance of exploitation in the next 30 days.
Description
Multiple unspecified vulnerabilities in GraphicsMagick before 1.2.4 allow remote attackers to cause a denial of service (crash, infinite loop, or memory consumption) via (a) unspecified vectors in the (1) AVI, (2) AVS, (3) DCM, (4) EPT, (5) FITS, (6) MTV, (7) PALM, (8) RLA, and (9) TGA decoder readers; and (b) the GetImageCharacteristics function in magick/image.c, as reachable from a crafted (10) PNG, (11) JPEG, (12) BMP, or (13) TIFF file.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Graphicsmagick | Graphicsmagick | 1.0 |
| Graphicsmagick | Graphicsmagick | 1.0.4 |
| Graphicsmagick | Graphicsmagick | 1.0.6 |
| Graphicsmagick | Graphicsmagick | 1.1 |
| Graphicsmagick | Graphicsmagick | 1.1.3 |
| Graphicsmagick | Graphicsmagick | 1.1.4 |
| Graphicsmagick | Graphicsmagick | 1.1.5 |
| Graphicsmagick | Graphicsmagick | 1.1.6 |
| Graphicsmagick | Graphicsmagick | 1.1.8 |
| Graphicsmagick | Graphicsmagick | 1.1.9 |
| Graphicsmagick | Graphicsmagick | 1.1.10 |
| Graphicsmagick | Graphicsmagick | 1.1.11 |
| Graphicsmagick | Graphicsmagick | 1.1.12 |
| Graphicsmagick | Graphicsmagick | 1.2 |
| Graphicsmagick | Graphicsmagick | 1.2.18 |
References
- http://secunia.com/advisories/30879Vendor Advisory
- http://secunia.com/advisories/30879Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-3134?
How severe is CVE-2008-3134?
How do I fix CVE-2008-3134?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-3128Directory traversal vulnerability in search.php in Pivot 1.4…
- CVE-2008-3129Multiple SQL injection vulnerabilities in index.php in Catvi…
- CVE-2008-3130Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2008-3131SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alp…
- CVE-2008-3132SQL injection vulnerability in the beamospetition (com_beamo…
- CVE-2008-3133SQL injection vulnerability in admin/index.php in BareNuked …
- CVE-2008-3135Soldner Secret Wars 33724 and earlier allows remote attacker…
- CVE-2008-3136SQL injection vulnerability in catalogue.php in AShop Deluxe…
- CVE-2008-3137The GSM SMS dissector in Wireshark (formerly Ethereal) 0.99.…
- CVE-2008-3138The (1) PANA and (2) KISMET dissectors in Wireshark (formerl…
- CVE-2008-3139The RTMPT dissector in Wireshark (formerly Ethereal) 0.99.8 …
- CVE-2008-3140The syslog dissector in Wireshark (formerly Ethereal) 1.0.0 …
Are you affected by CVE-2008-3134?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
