PT-2019-5847 · Imagemagick+5 · Imagemagick+5
Guilherme De Almeida Suckevicz
+1
·
Published
2019-10-13
·
Updated
2024-10-15
·
CVE-2020-27772
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 7.0.9-0
Description
A flaw was found in ImageMagick in coders/bmp.c, related to an integer overflow of the value. This could allow a remote attacker to cause a denial of service using a specially crafted file. The issue is triggered when a crafted file is processed by ImageMagick, leading to undefined behavior in the form of values outside the range of type
unsigned int. This would most likely impact application availability but could potentially cause other problems related to undefined behavior.Recommendations
For ImageMagick versions prior to 7.0.9-0, update to version 7.0.9-0 or later to resolve the issue. As a temporary workaround, consider restricting the processing of crafted files to minimize the risk of exploitation.
Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Imagemagick
Linuxmint
Suse
Ubuntu