#1149973 graphicsmagick: CVE-2026-103118

Package:
src:graphicsmagick
Source:
src:graphicsmagick
Submitter:
Salvatore Bonaccorso
Date:
2026-10-06 16:37:04 UTC
Severity:
normal
Tags:
#1149973#5
Date:
2026-10-04 20:05:03 UTC
From:
To:
Hi,

The following vulnerability was published for graphicsmagick.

CVE-2026-103118[0]:
| A vulnerability was detected in GraphicsMagick up to 1.3.47.
| Affected by this vulnerability is the function ExtractPostscript of
| the file coders/wpg.c of the component WPG File Handler. Performing
| a manipulation results in uncontrolled recursion. The attack may be
| initiated remotely. The patch is named 627b5b1b2fc2. It is suggested
| to install a patch to address this issue. The vendor was contacted
| early, responded in a very professional manner and quickly released
| a fixed version of the affected product.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-103118
https://www.cve.org/CVERecord?id=CVE-2026-103118
[1] https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/627b5b1b2fc2873550fde7777c9796ad001f89cc

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

#1149973#10
Date:
2026-10-06 16:35:04 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
graphicsmagick, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1149973@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Laszlo Boszormenyi (GCS) <gcs@debian.org> (supplier of updated graphicsmagick package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Tue, 06 Oct 2026 17:56:40 +0200
Source: graphicsmagick
Architecture: source
Version: 1.4+really1.3.48-2
Distribution: unstable
Urgency: high
Maintainer: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Changed-By: Laszlo Boszormenyi (GCS) <gcs@debian.org>
Closes: 1149973
Changes:
 graphicsmagick (1.4+really1.3.48-2) unstable; urgency=high
 .
   * Fix CVE-2026-103118: limit recursion under ExtractPostscript() to
     avoid stack exhaustion given crafted WPG files (closes: #1149973).
Checksums-Sha1:
 2037faeb07332aa08951340665f68983490a8ebd 3026 graphicsmagick_1.4+really1.3.48-2.dsc
 2718e368546708c2f8e32653fb5e149f22566011 165832 graphicsmagick_1.4+really1.3.48-2.debian.tar.xz
Checksums-Sha256:
 914162be5e602a772516f60a45200358031b4daf4241c8117307ba9358c95fd4 3026 graphicsmagick_1.4+really1.3.48-2.dsc
 073ee661bc6e552b6e392b7845a9a2cc131b7ea2a76eb224be96f6b505b94e04 165832 graphicsmagick_1.4+really1.3.48-2.debian.tar.xz
Files:
 a186c1434be1ed396e47e7f6627cf453 3026 graphics optional graphicsmagick_1.4+really1.3.48-2.dsc
 acb9d4419b2a7fa20e17d99d85b9414b 165832 graphics optional graphicsmagick_1.4+really1.3.48-2.debian.tar.xz
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEfYh9yLp7u6e4NeO63OMQ54ZMyL8FAmrFIG8ACgkQ3OMQ54ZM
yL/hgQ//VrgMBosSabBe4jWsF8OyP8MgDwkAac5FGQw/lzMYM0Cw4XYwEWtEb0Nz
eajoziWvaAjwpcdvfmmDcikXEZk+YACLDjiq1YdIHcRXpqny8AteHwpC8PiDMQGs
vlPEZzoe5ThZ4CvClf10MYFr2BM1V+HrLJh86XfWgYYnQEhkFq1n+K8dmsgWh7Rg
cEie+HJ80XdTA848fF091HPzmnXzQL9CQtxYhB2NJt0z2RqrKFjf38K0B79A8CfG
ge1H+PEKQ7epUvfMWVL/+tiMuOAa1bNxJOKL0ZV1O0h0yDYjM0c++2FGQBZT8ZSl
byadFMolzQXGzTfSZ/qTsKHv5S1aDiuT8pGyELHw1NW+tz2BXo4Soab8DPonfMaK
ihEhAU9hy4Ld6mHYlKzroswQ+4BRJNOmwCz9edYzdljGcGx0VSqvFUh41hNFEInN
iyMqDw8ImggizQLCsT4Ni3QLPpgnpFntCavIquCsBx9FTy4cxG7yCv9U+ZuPEqGb
8ieQYjYpdaT01eS+3PrPE6daiPOWjdHQ+5iqjkdCeXwjwXdRtCf8H5MLy8LflzbQ
WDUN5Xr5g6mDM2VCn3rZ99jUakqTONpQxY1ike2vwJX3i3wYlKqqrM5sn1JOknfn
8+/VzdfdNFHgmzFDNEtEjxVfNrvHPnUoRU8q5PploZoBx7e1H7w=
=wvmo
-----END PGP SIGNATURE-----