PT-2019-5857 · Imagemagick+5 · Imagemagick+5
Published
2019-10-05
·
Updated
2024-10-15
·
CVE-2020-27758
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 7.0.8-68
Description
A flaw was found in ImageMagick in coders/txt.c, related to an integer overflow of the value. This issue could allow a remote attacker to cause a denial of service using a specially crafted file. The exploitation of this flaw may lead to undefined behavior, potentially causing problems related to application availability.
Recommendations
For versions prior to 7.0.8-68, update to version 7.0.8-68 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
coders/txt.c component until a patch is available. Avoid processing crafted files that could trigger undefined behavior in the form of values outside the range of type unsigned long long.Exploit
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Imagemagick
Linuxmint
Suse
Ubuntu