PT-2019-5838 · Imagemagick+5 · Imagemagick+5

·

CVE-2020-27770

·

Published

2019-10-05

·

Updated

2024-10-15

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.0.8-68
Description The issue is related to a missing check for a 0 value of replace extent in the SubstituteString() function, which can cause an offset p to overflow. This could be triggered by a crafted input file processed by ImageMagick, potentially impacting application availability. The flaw can be exploited by a remote attacker using a specially crafted file.
Recommendations For ImageMagick versions prior to 7.0.8-68, update to version 7.0.8-68 or later to resolve the issue. As a temporary workaround, consider restricting the use of crafted input files that could trigger the overflow in the SubstituteString() function.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3182
ALT-PU-2020-1405
BDU:2021-03381
CVE-2020-27770
DLA-2602-1
DLA-3357-1
DLA-3357-2
OESA-2021-1007
OPENSUSE-SU-2021:0136-1
OPENSUSE-SU-2021:0148-1
OPENSUSE-SU-2021_0136-1
OPENSUSE-SU-2021_0148-1
OPENSUSE-SU-2024:11564-1
SUSE-SU-2021:0153-1
SUSE-SU-2021:0156-1
SUSE-SU-2021:0199-1
USN-4988-1
USN-5335-1
USN-7068-1

Affected Products

Alt Linux
Astra Linux
Imagemagick
Linuxmint
Suse
Ubuntu