First published: Sun Jun 07 2020(Updated: )
ImageMagick 7.0.9-27 through 7.0.10-17 has a heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c during TIFF image decoding.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | >=7.0.9-27<=7.0.10-17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-13902 is considered a high-severity vulnerability due to its potential for remote exploitation.
To fix CVE-2020-13902, upgrade ImageMagick to version 7.0.10-18 or later.
CVE-2020-13902 is classified as a heap-based buffer over-read vulnerability.
ImageMagick versions 7.0.9-27 through 7.0.10-17 are affected by CVE-2020-13902.
Yes, CVE-2020-13902 can potentially lead to data leakage due to the nature of the buffer over-read.