ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of a misplaced assignment.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*",
"cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "16.04"
},
{
"last_affected": "18.04"
},
{
"last_affected": "19.04"
},
{
"last_affected": "19.10"
}
],
"vendor_product": "canonical:ubuntu_linux",
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*",
"cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "8.0"
},
{
"last_affected": "9.0"
},
{
"last_affected": "10.0"
}
],
"vendor_product": "debian:debian_linux",
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:a:imagemagick:imagemagick:7.0.8-50:q16:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "7.0.8-50-q16"
},
{
"last_affected": "7.0.8-50-q16"
}
],
"vendor_product": "imagemagick:imagemagick",
"source": "CPE_FIELD"
},
{
"cpes": [
"cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*",
"cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "15.0"
},
{
"last_affected": "15.1"
}
],
"vendor_product": "opensuse:leap",
"source": "CPE_FIELD"
}
]
}"2026-05-18T17:42:03Z"
[
{
"signature_version": "v1",
"digest": {
"line_hashes": [
"219707937630122763560001536482673152502",
"301314171960501209191339723357525537160",
"39745282696061110951357254645360303614",
"193647398643077428190764862151963985319",
"317175198683672260677478595904029961129",
"331103141952356089566155178080339761980",
"208860185305730238549952908594482552465",
"191554334367101042462272792348364098863",
"251469381905454677448473595287462568586",
"68682566748185754501242263673426332532"
],
"threshold": 0.9
},
"id": "CVE-2019-13304-452f5053",
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick/commit/7689875ef64f34141e7292f6945efdf0530b4a5e",
"target": {
"file": "coders/pnm.c"
},
"signature_type": "Line"
},
{
"signature_version": "v1",
"digest": {
"function_hash": "76446368930900859138829636444068436244",
"length": 21985.0
},
"id": "CVE-2019-13304-9d4b425d",
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick/commit/7689875ef64f34141e7292f6945efdf0530b4a5e",
"target": {
"function": "WritePNMImage",
"file": "coders/pnm.c"
},
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13304.json"
"2026-05-18T17:42:03Z"
[
{
"signature_version": "v1",
"digest": {
"line_hashes": [
"219707937630122763560001536482673152502",
"301314171960501209191339723357525537160",
"39745282696061110951357254645360303614",
"193647398643077428190764862151963985319",
"317175198683672260677478595904029961129",
"331103141952356089566155178080339761980",
"208860185305730238549952908594482552465",
"223298258395674198923092237956824505086",
"136093366047081782534432463312274729429",
"221104929025802232976201896599260669426"
],
"threshold": 0.9
},
"id": "CVE-2019-13304-a337d95d",
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick6/commit/bfa3b9610c83227894c92b0d312ad327fceb6241",
"target": {
"file": "coders/pnm.c"
},
"signature_type": "Line"
},
{
"signature_version": "v1",
"digest": {
"function_hash": "178887915414222179175710026286897457694",
"length": 21296.0
},
"id": "CVE-2019-13304-c76f6168",
"deprecated": false,
"source": "https://github.com/imagemagick/imagemagick6/commit/bfa3b9610c83227894c92b0d312ad327fceb6241",
"target": {
"function": "WritePNMImage",
"file": "coders/pnm.c"
},
"signature_type": "Function"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13304.json"