CVE-2026-103118

⚪ Do wiadomości

Nieograniczona rekurencja w GraphicsMagick umożliwia zdalne ataki.

CVSS
4.3
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)

A vulnerability was detected in GraphicsMagick up to 1.3.47. Affected by this vulnerability is the function ExtractPostscript of the file coders/wpg.c of the component WPG File Handler. Performing a manipulation results in uncontrolled recursion. The attack may be initiated remotely. The patch is named 627b5b1b2fc2. It is suggested to install a patch to address this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS4.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.3%
Opublikowano (NVD)2026-09-30 14:17:27 UTC
Ostatnia modyfikacja (NVD)2026-10-02 17:17:01 UTC
Referencje