PT-2019-5852 · Imagemagick+5 · Imagemagick+5

CVE-2020-25666

·

Published

2019-10-13

·

Updated

2024-10-15

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.0.9-0
Description The issue is related to an integer overflow in the HistogramCompare() function within the MagickCore/histogram.c component of ImageMagick. This overflow can occur during simple math calculations involving rgb values and the count value for a color. The flaw could impact application reliability if ImageMagick processes a crafted input file, potentially leading to a denial of service.
Recommendations For versions prior to 7.0.9-0, update to version 7.0.9-0 or later to resolve the issue. As a temporary workaround, consider restricting the processing of crafted input files until the update is applied.

Exploit

Fix

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3182
ALT-PU-2020-1405
BDU:2021-03411
CVE-2020-25666
DLA-2602-1
DLA-3357-1
DLA-3357-2
OESA-2021-1148
OPENSUSE-SU-2021:0136-1
OPENSUSE-SU-2021:0148-1
OPENSUSE-SU-2021_0136-1
OPENSUSE-SU-2021_0148-1
OPENSUSE-SU-2024:11564-1
SUSE-SU-2021:0153-1
SUSE-SU-2021:0156-1
SUSE-SU-2021:0199-1
SUSE-SU-2021:14598-1
SUSE-SU-2021_14598-1
USN-4988-1
USN-7068-1

Affected Products

Alt Linux
Astra Linux
Imagemagick
Linuxmint
Suse
Ubuntu