PT-2021-3554 · Unknown+5 · Imagemagick+5

Zhang Xiaohui

·

Published

2021-01-15

·

Updated

2024-12-17

·

CVE-2021-20176

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions 6.9.11-57 through 7.0.10-57
Description The issue is related to a divide-by-zero flaw in the gem.c file of ImageMagick, which can be exploited by submitting a crafted file to trigger undefined behavior. This flaw poses a threat to system availability, allowing a remote attacker to cause a denial of service.
Recommendations For versions 6.9.11-57 through 7.0.10-57, consider disabling the processing of crafted files until a patch is available. Restrict access to the gem.c file to minimize the risk of exploitation. Avoid using the vulnerable function in the gem.c file until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Divide By Zero

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1438
ALT-PU-2024-2243
BDU:2021-03651
CVE-2021-20176
DLA-2602-1
DLA-3429-1
OESA-2021-1110
OPENSUSE-SU-2021:1583-1
OPENSUSE-SU-2021:3996-1
OPENSUSE-SU-2021_1583-1
OPENSUSE-SU-2021_3996-1
SUSE-SU-2021:0528-1
SUSE-SU-2021:3996-1
SUSE-SU-2021_3996-1
SUSE-SU-2023:4634-1
USN-4988-1
USN-5335-1
USN-7164-1

Affected Products

Alt Linux
Astra Linux
Imagemagick
Linuxmint
Suse
Ubuntu