ImageMagick 7.0.8-50 Q16 has a heap-based buffer over-read at MagickCore/threshold.c in AdaptiveThresholdImage because a height of zero is mishandled.
{
"unresolved_ranges": [
{
"vendor_product": "canonical:ubuntu_linux",
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "16.04"
},
{
"last_affected": "18.04"
},
{
"last_affected": "19.04"
},
{
"last_affected": "19.10"
}
]
},
{
"vendor_product": "debian:debian_linux",
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8.0"
},
{
"last_affected": "9.0"
},
{
"last_affected": "10.0"
}
]
},
{
"vendor_product": "imagemagick:imagemagick",
"cpes": [
"cpe:2.3:a:imagemagick:imagemagick:7.0.8-50:q16:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "7.0.8-50-q16"
},
{
"last_affected": "7.0.8-50-q16"
}
]
},
{
"vendor_product": "opensuse:leap",
"cpes": [
"cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"
],
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "15.0"
},
{
"last_affected": "15.1"
}
]
}
]
}[
{
"source": "https://github.com/imagemagick/imagemagick/commit/604588fc35c7585abb7a9e71f69bb82e4389fefc",
"signature_version": "v1",
"target": {
"function": "AdaptiveThresholdImage",
"file": "MagickCore/threshold.c"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 3884.0,
"function_hash": "293774822276901381121692040320794529384"
},
"id": "CVE-2019-13297-95498ca3"
},
{
"source": "https://github.com/imagemagick/imagemagick/commit/604588fc35c7585abb7a9e71f69bb82e4389fefc",
"signature_version": "v1",
"target": {
"file": "MagickCore/threshold.c"
},
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"117598967055875212079018179199311819921",
"133681935158990302008425794363574872644",
"208702601358116156630648525031441984189",
"332840740244699029697185092650489018364"
],
"threshold": 0.9
},
"id": "CVE-2019-13297-b572764d"
}
]
"2026-05-18T17:42:01Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13297.json"
[
{
"source": "https://github.com/imagemagick/imagemagick6/commit/35c7032723d85eee7318ff6c82f031fa2666b773",
"signature_version": "v1",
"target": {
"function": "AdaptiveThresholdImage",
"file": "magick/threshold.c"
},
"signature_type": "Function",
"deprecated": false,
"digest": {
"length": 4717.0,
"function_hash": "235955745071647266351482265208538814416"
},
"id": "CVE-2019-13297-20d86cae"
},
{
"source": "https://github.com/imagemagick/imagemagick6/commit/35c7032723d85eee7318ff6c82f031fa2666b773",
"signature_version": "v1",
"target": {
"file": "magick/threshold.c"
},
"signature_type": "Line",
"deprecated": false,
"digest": {
"line_hashes": [
"117598967055875212079018179199311819921",
"133681935158990302008425794363574872644",
"297672351830198098392830777990473090885",
"119584949241414408407604300930421357817"
],
"threshold": 0.9
},
"id": "CVE-2019-13297-dc7f6b94"
}
]
"2026-05-18T17:42:01Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13297.json"