PT-2020-5522 · Imagemagick+5 · Imagemagick+5

Guilherme De Almeida Suckevicz

+1

·

Published

2019-11-25

·

Updated

2024-10-15

·

CVE-2020-27755

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.0.9-0
Description The issue is related to the function SetImageExtent() in /MagickCore/image.c of the ImageMagick console graphic editor. It is caused by incorrect handling of image depth size, leading to memory leaks when an invalid size is encountered. This can be triggered by a specially crafted input file, potentially causing denial of service due to its impact on application reliability.
Recommendations For versions prior to 7.0.9-0, update to version 7.0.9-0 or later to resolve the issue. As a temporary workaround, consider restricting the use of the SetImageExtent() function until a patch is applied. Avoid using crafted input files that could trigger the memory leak in the affected API endpoint until the issue is resolved.

Exploit

Fix

DoS

Memory Leak

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3182
ALT-PU-2020-1405
BDU:2021-01035
CVE-2020-27755
OESA-2021-1148
OPENSUSE-SU-2021:0136-1
OPENSUSE-SU-2021:0148-1
OPENSUSE-SU-2021_0136-1
OPENSUSE-SU-2021_0148-1
OPENSUSE-SU-2024:11564-1
SUSE-SU-2021:0153-1
SUSE-SU-2021:0156-1
SUSE-SU-2021:0199-1
SUSE-SU-2021:14598-1
SUSE-SU-2021_14598-1
USN-4988-1
USN-7068-1

Affected Products

Alt Linux
Astra Linux
Imagemagick
Linuxmint
Suse
Ubuntu