First published: Wed Nov 04 2020(Updated: )
In ImageMagick, there are three outside the range of representable values of type 'unsigned long' at coders/palm.c. Reference: <a href="https://github.com/ImageMagick/ImageMagick/issues/1726">https://github.com/ImageMagick/ImageMagick/issues/1726</a> Upstream patch: <a href="https://github.com/ImageMagick/ImageMagick/commit/db5e12e24f1378ce8c93a5c35991dcdd23a67bb0">https://github.com/ImageMagick/ImageMagick/commit/db5e12e24f1378ce8c93a5c35991dcdd23a67bb0</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | <6.9.10-69 | |
ImageMagick ImageMagick | >=7.0.0-0<7.0.9-0 | |
Debian Debian Linux | =9.0 | |
redhat/ImageMagick 7.0.9 | <0 | 0 |
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u4 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u2 8:6.9.11.60+dfsg-1.6+deb12u1 8:7.1.1.39+dfsg1-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27761 is a vulnerability in the WritePALMImage() function of ImageMagick that could lead to undefined behavior when processing a crafted input file.
The severity of CVE-2020-27761 is medium, with a severity score of 3.3.
ImageMagick versions 6.9.7.4 to 6.9.10-69 and 7.0.0-0 to 7.0.9-0 are affected. Ubuntu versions 18.04 LTS (bionic), 20.04 LTS (focal), and 20.10 (groovy) with the appropriate ImageMagick packages installed are also affected. Debian versions 9.0 (stretch) and 10 (buster) with ImageMagick packages installed are affected as well. Red Hat with ImageMagick 7.0.9 packages installed is also affected.
On Ubuntu, you can fix CVE-2020-27761 by updating ImageMagick to version 8:6.9.7.4+dfsg-16ubuntu6.11 (for bionic), 8:6.9.10.23+dfsg-2.1ubuntu11.4 (for focal), or 8:6.9.10.23+dfsg-2.1ubuntu13.3 (for groovy).
On Debian, you can fix CVE-2020-27761 by updating ImageMagick to version 8:6.9.10.23+dfsg-2.1+deb10u5, 8:6.9.11.60+dfsg-1.3+deb11u1, or 8:6.9.11.60+dfsg-1.6.