First published: Mon Oct 26 2020(Updated: )
ImageMagick 7.0.8-68 there is a heap-buffer-overflow at coders/tiff.c in TIFFGetProfiles. Reference: <a href="https://github.com/ImageMagick/ImageMagick/issues/1748">https://github.com/ImageMagick/ImageMagick/issues/1748</a> Upstream patch: <a href="https://github.com/ImageMagick/ImageMagick/commit/986b5dff173413fa712db27eb677cdef15f0bab6">https://github.com/ImageMagick/ImageMagick/commit/986b5dff173413fa712db27eb677cdef15f0bab6</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/ImageMagick 7.0.9 | <0 | 0 |
ImageMagick | <6.9.10-69 | |
ImageMagick | >=7.0.0-0<7.0.9-0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25667 has a high severity due to the potential for a heap buffer overflow that can lead to arbitrary code execution.
To fix CVE-2020-25667, update ImageMagick to version 7.0.9 or later, which includes the necessary patches.
CVE-2020-25667 affects ImageMagick versions prior to 7.0.9 and all versions of ImageMagick 6.9.10-69 and earlier.
CVE-2020-25667 can cause a heap buffer overflow, which may lead to denial of service or execution of arbitrary code.
More information about CVE-2020-25667 can be found in the community discussions and the GitHub repository for ImageMagick.