{"id":"ECHO-28c1-57be-0ba4","summary":"CVE-2008-3134 targets GraphicsMagick before 1.2.4, not ImageMagick. NVD only lists\nGraphicsMagick in CPE entries. ImageMagick developers reviewed this CVE at publication\nand confirmed their releases were not affected (Debian bug #559775). GraphicsMagick\nforked from ImageMagick in 2002, six years before this CVE — codebases are entirely\nindependent. The vulnerable GetImageCharacteristics function does not exist in\nImageMagick 7.x. Modern ImageMagick uses centralized resource limits (SetImageExtent,\nAcquireMagickResource, policy.xml) providing DoS protection across all decoders.\nDebian rates this \"unimportant\" for imagemagick and has never produced a fix in 18 years.\n","modified":"2026-09-15T03:33:35.850065092Z","published":"2025-09-15T01:08:37.239228Z","withdrawn":"2026-02-12T16:15:04.462Z","upstream":["CVE-2008-3134"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2008-3134"}],"affected":[{"package":{"name":"imagemagick","ecosystem":"Echo","purl":"pkg:deb/echo/imagemagick"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8:7.1.1.43+dfsg1-1+deb13u4"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-28c1-57be-0ba4.json"}}],"schema_version":"1.9.0"}