First published: Mon Oct 26 2020(Updated: )
In ImageMagick, there is a heap-buffer-overflow at MagickCore/quantum-private.h:227:12 in PopShortPixel. Reference: <a href="https://github.com/ImageMagick/ImageMagick/issues/1716">https://github.com/ImageMagick/ImageMagick/issues/1716</a> Upstream patch: <a href="https://github.com/ImageMagick/ImageMagick/commit/1f450bb5ba53d275de6d1cd086c98a0b549ad393">https://github.com/ImageMagick/ImageMagick/commit/1f450bb5ba53d275de6d1cd086c98a0b549ad393</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | <6.9.10-68 | |
ImageMagick ImageMagick | >=7.0.8<7.0.8-68 | |
Fedoraproject Fedora | =34 | |
redhat/ImageMagick 7.0.8 | <68 | 68 |
redhat/ImageMagick 6.9.10 | <68 | 68 |
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u4 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u2 8:6.9.11.60+dfsg-1.6+deb12u1 8:7.1.1.43+dfsg1-1 | |
Fedora | =34 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25664 is a vulnerability in the PNG coder of ImageMagick that allows for an out-of-bounds write and can be exploited by an attacker.
CVE-2020-25664 has a severity rating of 6.1 (medium).
ImageMagick versions 8:6.9.11.24+dfsg-1 and earlier, 8:6.8.9.9-7ubuntu5.16+ and earlier, ImageMagick 7.0.8-68 and earlier, and ImageMagick 6.9.10-68 and earlier are affected.
To fix CVE-2020-25664, update ImageMagick to version 8:6.9.11.24+dfsg-1.3+deb11u1 or 8:6.9.11.60+dfsg-1.6 or later.
You can find more information about CVE-2020-25664 on the CVE Mitre website, Ubuntu security notices, and NIST NVD.