PT-2019-5854 · Imagemagick+5 · Imagemagick+5

Guilherme De Almeida Suckevicz

·

Published

2019-10-08

·

Updated

2023-03-18

·

CVE-2020-25675

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.0.9-0
Description The issue is related to the CropImage() and CropImageToTiles() routines in MagickCore/transform.c, where rounding calculations on unconstrained pixel offsets caused undefined behavior, including integer overflow and out-of-range values. This could lead to a negative impact on application availability when processing untrusted input data. The problem was identified by UndefinedBehaviorSanitizer.
Recommendations For ImageMagick versions prior to 7.0.9-0, update to version 7.0.9-0 or later to resolve the issue. As a temporary workaround, consider restricting the processing of untrusted input data until the update is applied.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3182
ALT-PU-2020-1405
BDU:2021-03415
CVE-2020-25675
DLA-2602-1
DLA-3357-1
DLA-3357-2
OESA-2021-1148
OPENSUSE-SU-2021:0136-1
OPENSUSE-SU-2021:0148-1
OPENSUSE-SU-2021_0136-1
OPENSUSE-SU-2021_0148-1
SUSE-SU-2021:0153-1
SUSE-SU-2021:0156-1
SUSE-SU-2021:0199-1
USN-4988-1

Affected Products

Alt Linux
Astra Linux
Imagemagick
Linuxmint
Suse
Ubuntu