ECHO-28c1-57be-0ba4

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-28c1-57be-0ba4.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-28c1-57be-0ba4
Upstream
Withdrawn
2026-02-12T16:15:04Z
Published
2025-09-15T01:08:37Z
Modified
2026-09-15T03:33:35Z
Summary
CVE-2008-3134 targets GraphicsMagick before 1.2.4, not ImageMagick. NVD only lists GraphicsMagick in CPE entries. ImageMagick developers reviewed this CVE at publication and confirmed their releases were not affected (Debian bug #559775). GraphicsMagick forked from ImageMagick in 2002, six years before this CVE — codebases are entirely independent. The vulnerable GetImageCharacteristics function does not exist in ImageMagick 7.x. Modern ImageMagick uses centralized resource limits (SetImageExtent, AcquireMagickResource, policy.xml) providing DoS protection across all decoders. Debian rates this "unimportant" for imagemagick and has never produced a fix in 18 years.
Details
References

Affected packages

Echo / imagemagick

Package

Name
imagemagick
Purl
pkg:deb/echo/imagemagick

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8:7.1.1.43+dfsg1-1+deb13u4

Database specific

source
"https://advisory.echohq.com/osv/ECHO-28c1-57be-0ba4.json"