PT-2019-5730 · Imagemagick+5 · Imagemagick+5

Guilherme De Almeida Suckevicz

+1

·

Published

2019-10-14

·

Updated

2024-10-15

·

CVE-2020-27754

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 6.9.10-69 and 7.0.8-69
Description The issue is related to the IntensityCompare() function in the /magick/quantize.c file of the ImageMagick console graphic editor, which is associated with an integer overflow. This can be exploited by a remote attacker using a specially crafted file, potentially leading to a denial of service. The flaw is mitigated by introducing the ConstrainPixelIntensity() function, which ensures pixel intensities are within proper bounds in case of an overflow.
Recommendations For versions prior to 6.9.10-69 and 7.0.8-69, update to version 6.9.10-69 or 7.0.8-69, or later, to resolve the issue. As a temporary workaround, consider restricting the use of the IntensityCompare() function in /magick/quantize.c until a patch is applied. Additionally, avoid using the PixelPacketIntensity() function with crafted input files to minimize the risk of exploitation.

Exploit

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3182
ALT-PU-2020-1405
BDU:2021-01016
CVE-2020-27754
DLA-2602-1
DLA-3357-1
DLA-3357-2
OESA-2021-1050
OPENSUSE-SU-2021:0136-1
OPENSUSE-SU-2021:0148-1
OPENSUSE-SU-2021_0136-1
OPENSUSE-SU-2021_0148-1
SUSE-SU-2021:0153-1
SUSE-SU-2021:0156-1
SUSE-SU-2021:0199-1
SUSE-SU-2021:14598-1
SUSE-SU-2021_14598-1
USN-4988-1
USN-7068-1

Affected Products

Alt Linux
Astra Linux
Imagemagick
Linuxmint
Suse
Ubuntu