CVE-2020-27755: Medium severity imagemagick vulnerability

Published Nov 3, 2020
·
Updated

In ImageMagick, there are memory leaks detected in ResizeMagickMemory at MagickCore/memory.c.

Reference: https://github.com/ImageMagick/ImageMagick/issues/1756

Upstream patch: https://github.com/ImageMagick/ImageMagick/commit/f28e9e56e1b56d4e1f09d2a56d70892ae295d6a4

Other sources

in SetImageExtent() of /MagickCore/image.c, an incorrect image depth size can cause a memory leak because the code which checks for the proper image depth size does not reset the size in the event there is an invalid size. The patch resets the depth to a proper size before throwing an exception. The memory leak can be triggered by a crafted input file that is processed by ImageMagick and could cause an impact to application reliability, such as denial of service. This flaw affects ImageMagick versions prior to 7.0.9-0.

Launchpad

Affected Software

4 affected componentsFixes available
redhat/ImageMagick 7.0.9<0
0
ImageMagick<6.9.10-69
ImageMagick>=7.0.0-0<7.0.9-0
debian/imagemagick
8:6.9.11.60+dfsg-1.3+deb11u48:6.9.11.60+dfsg-1.3+deb11u58:6.9.11.60+dfsg-1.6+deb12u28:6.9.11.60+dfsg-1.6+deb12u18:7.1.1.43+dfsg1-18:7.1.1.47+dfsg1-1

Event History

Dec 8, 2020
CVE Published
via MITRE·09:57 PM
Data Sourced
via MITRE·09:57 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:47 PM
Description
Oct 19, 2024
Data Sourced
via Ubuntu·09:19 AM
RemedyDescriptionSeverityAffected Software
Apr 6, 2025
Data Sourced
via Debian·11:43 PM
DescriptionAffected Software

Frequently Asked Questions

1

What is CVE-2020-27755?

CVE-2020-27755 is a vulnerability in the SetImageExtent() function of ImageMagick that can cause a memory leak due to an incorrect image depth size.

2

What is the severity of CVE-2020-27755?

The severity of CVE-2020-27755 is medium with a severity value of 3.3.

3

Which software is affected by CVE-2020-27755?

ImageMagick versions 6.9.11.24+dfsg-1, 6.9.7.4+dfsg-16ubuntu6.11, 6.9.10.23+dfsg-2.1ubuntu11.4, 6.9.10.23+dfsg-2.1ubuntu13.3, and 7.0.9 are affected by CVE-2020-27755.

4

How do I fix CVE-2020-27755?

To fix CVE-2020-27755, update ImageMagick to version 6.9.11.60+dfsg-1.3+deb11u1 or 6.9.11.60+dfsg-1.6.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203