ImageMagick 7.0.8-50 Q16 has a stack-based buffer overflow at coders/pnm.c in WritePNMImage because of off-by-one errors.
{
"unresolved_ranges": [
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "7.0.8-50-q16"
}
],
"cpe": "cpe:2.3:a:imagemagick:imagemagick:7.0.8-50:q16:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "16.04"
}
],
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "18.04"
}
],
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "19.04"
}
],
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:19.04:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "19.10"
}
],
"cpe": "cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "8.0"
}
],
"cpe": "cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "9.0"
}
],
"cpe": "cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "15.0"
}
],
"cpe": "cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*"
},
{
"source": "CPE_FIELD",
"extracted_events": [
{
"last_affected": "15.1"
}
],
"cpe": "cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*"
}
]
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13306.json"
[
{
"target": {
"file": "coders/pnm.c"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/imagemagick/imagemagick/commit/e92040ea6ee2a844ebfd2344174076795a4787bd",
"id": "CVE-2019-13306-a897742d",
"digest": {
"threshold": 0.9,
"line_hashes": [
"106194549059593632269021515242205683326",
"73206001765135714412094639179018116291",
"160821921610913074378187192959977773534",
"54722723182597058330938219509802193063",
"106194549059593632269021515242205683326",
"73206001765135714412094639179018116291",
"160821921610913074378187192959977773534",
"54722723182597058330938219509802193063"
]
}
},
{
"target": {
"function": "WritePNMImage",
"file": "coders/pnm.c"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/imagemagick/imagemagick/commit/e92040ea6ee2a844ebfd2344174076795a4787bd",
"id": "CVE-2019-13306-e8d33e0c",
"digest": {
"function_hash": "129115947922196402685183886624375644393",
"length": 21985.0
}
}
]
"2026-04-11T21:45:03Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-13306.json"
[
{
"target": {
"function": "WritePNMImage",
"file": "coders/pnm.c"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"source": "https://github.com/imagemagick/imagemagick6/commit/cb5ec7d98195aa74d5ed299b38eff2a68122f3fa",
"id": "CVE-2019-13306-5229bcfb",
"digest": {
"function_hash": "62266670660684400905173600749239523842",
"length": 21296.0
}
},
{
"target": {
"file": "coders/pnm.c"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"source": "https://github.com/imagemagick/imagemagick6/commit/cb5ec7d98195aa74d5ed299b38eff2a68122f3fa",
"id": "CVE-2019-13306-d4666a0a",
"digest": {
"threshold": 0.9,
"line_hashes": [
"106194549059593632269021515242205683326",
"73206001765135714412094639179018116291",
"160821921610913074378187192959977773534",
"54722723182597058330938219509802193063",
"106194549059593632269021515242205683326",
"73206001765135714412094639179018116291",
"160821921610913074378187192959977773534",
"54722723182597058330938219509802193063"
]
}
}
]
"2026-04-11T21:45:03Z"