PT-2019-5857 · Imagemagick+5 · Imagemagick+5

Published

2019-10-05

·

Updated

2024-10-15

·

CVE-2020-27758

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.0.8-68
Description A flaw was found in ImageMagick in coders/txt.c, related to an integer overflow of the value. This issue could allow a remote attacker to cause a denial of service using a specially crafted file. The exploitation of this flaw may lead to undefined behavior, potentially causing problems related to application availability.
Recommendations For versions prior to 7.0.8-68, update to version 7.0.8-68 or later to resolve the issue. As a temporary workaround, consider restricting the use of the coders/txt.c component until a patch is available. Avoid processing crafted files that could trigger undefined behavior in the form of values outside the range of type unsigned long long.

Exploit

Fix

Integer Overflow

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3182
ALT-PU-2020-1405
BDU:2021-03418
CVE-2020-27758
DLA-2602-1
DLA-3357-1
DLA-3357-2
OESA-2021-1148
OPENSUSE-SU-2021:0136-1
OPENSUSE-SU-2021:0148-1
OPENSUSE-SU-2021_0136-1
OPENSUSE-SU-2021_0148-1
SUSE-SU-2021:0153-1
SUSE-SU-2021:0156-1
USN-4988-1
USN-7068-1

Affected Products

Alt Linux
Astra Linux
Imagemagick
Linuxmint
Suse
Ubuntu