First published: Tue Nov 03 2020(Updated: )
In ImageMagick, there are memory leaks detected in ResizeMagickMemory at MagickCore/memory.c. Reference: <a href="https://github.com/ImageMagick/ImageMagick/issues/1756">https://github.com/ImageMagick/ImageMagick/issues/1756</a> Upstream patch: <a href="https://github.com/ImageMagick/ImageMagick/commit/f28e9e56e1b56d4e1f09d2a56d70892ae295d6a4">https://github.com/ImageMagick/ImageMagick/commit/f28e9e56e1b56d4e1f09d2a56d70892ae295d6a4</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | <6.9.10-69 | |
ImageMagick ImageMagick | >=7.0.0-0<7.0.9-0 | |
redhat/ImageMagick 7.0.9 | <0 | 0 |
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u4 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u2 8:6.9.11.60+dfsg-1.6+deb12u1 8:7.1.1.39+dfsg1-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27755 is a vulnerability in the SetImageExtent() function of ImageMagick that can cause a memory leak due to an incorrect image depth size.
The severity of CVE-2020-27755 is medium with a severity value of 3.3.
ImageMagick versions 6.9.11.24+dfsg-1, 6.9.7.4+dfsg-16ubuntu6.11, 6.9.10.23+dfsg-2.1ubuntu11.4, 6.9.10.23+dfsg-2.1ubuntu13.3, and 7.0.9 are affected by CVE-2020-27755.
To fix CVE-2020-27755, update ImageMagick to version 6.9.11.60+dfsg-1.3+deb11u1 or 6.9.11.60+dfsg-1.6.