PT-2021-4530 · Unknown+4 · Imagemagick+4
Hifoolnoop
·
Published
2021-02-02
·
Updated
2024-03-01
·
CVE-2021-20245
CVSS v2.0
7.1
High
| Vector | AV:N/AC:M/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
ImageMagick (affected versions not specified)
Description
A flaw was found in ImageMagick in coders/webp.c, related to a lack of division by zero check. This issue can be exploited by a remote attacker who submits a crafted file that is processed by ImageMagick, potentially triggering undefined behavior in the form of math division by zero. The highest threat from this issue is to system availability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Astra Linux
Imagemagick
Linuxmint
Ubuntu