Description
A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.8-69.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2602-1 | imagemagick security update |
Debian DLA |
DLA-3357-1 | imagemagick security update |
EUVD |
EUVD-2020-20270 | A flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned long`. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.8-69. |
Ubuntu USN |
USN-4988-1 | ImageMagick vulnerabilities |
Ubuntu USN |
USN-5335-1 | ImageMagick vulnerabilities |
Ubuntu USN |
USN-7068-1 | ImageMagick vulnerabilities |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-04T16:18:45.737Z
Reserved: 2020-10-27T00:00:00.000Z
Link: CVE-2020-27766
No data.
Status : Modified
Published: 2020-12-04T15:15:10.567
Modified: 2024-11-21T05:21:47.677
Link: CVE-2020-27766
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
EUVD
Ubuntu USN