First published: Tue Nov 03 2020(Updated: )
In ImageMagick, there are outside the range of representable values of type 'long' and signed integer overflow at MagickCore/quantize.c. Reference: <a href="https://github.com/ImageMagick/ImageMagick/issues/1754">https://github.com/ImageMagick/ImageMagick/issues/1754</a> Upstream patch: <a href="https://github.com/ImageMagick/ImageMagick6/commit/d5df600d43c8706df513a3273d09aee6f54a9233">https://github.com/ImageMagick/ImageMagick6/commit/d5df600d43c8706df513a3273d09aee6f54a9233</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | <6.9.10-69 | |
ImageMagick ImageMagick | >=7.0.8<7.0.8-69 | |
Debian Debian Linux | =9.0 | |
redhat/ImageMagick 6.9.10 | <69 | 69 |
redhat/ImageMagick 7.0.8 | <69 | 69 |
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u4 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u2 8:6.9.11.60+dfsg-1.6+deb12u1 8:7.1.1.39+dfsg1-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-27754 is medium.
CVE-2020-27754 affects ImageMagick versions 8:6.9.10.23+dfsg-2.1ubuntu11.4, 8:6.9.10.23+dfsg-2.1ubuntu13.3, 8:6.9.11.24+dfsg-1, and 8:6.9.7.4+dfsg-16ubuntu6.11.
To fix CVE-2020-27754 on Ubuntu, update ImageMagick to version 8:6.9.10.23+dfsg-2.1ubuntu11.4, 8:6.9.10.23+dfsg-2.1ubuntu13.3, 8:6.9.11.24+dfsg-1, or 8:6.9.7.4+dfsg-16ubuntu6.11.
To fix CVE-2020-27754 on Debian, update ImageMagick to version 8:6.9.10.23+dfsg-2.1+deb10u5, 8:6.9.11.60+dfsg-1.3+deb11u1, or 8:6.9.11.60+dfsg-1.6.
The Common Weakness Enumeration (CWE) ID for CVE-2020-27754 is 190.