CVE-2020-27763: Divide by Zero
A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.8-68.
Other sources
In ImageMagick, there is a Division by Zero at MagickCore/resize.c.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1718
Upstream patch: https://github.com/ImageMagick/ImageMagick/commit/43539e67a47d2f8de832d33a5b26dc2a7a12294f
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID of this flaw?
The vulnerability ID is CVE-2020-27763.
What is the severity level of CVE-2020-27763?
The severity level of CVE-2020-27763 is medium.
Which software is affected by CVE-2020-27763?
ImageMagick versions 8:6.9.7.4+dfsg-16ubuntu6.11, 8:6.9.10.23+dfsg-2.1ubuntu11.4, 8:6.9.10.23+dfsg-2.1ubuntu13.3, 8:6.9.11.24+dfsg-1, 7.0.0-0 to 7.0.8-68, and 9.0 on Debian Linux 9.0 are affected.
How can this vulnerability be exploited?
An attacker could exploit this vulnerability by submitting a crafted file that is processed by ImageMagick, triggering undefined behavior in the form of math division by zero.
Are there any known remedies for CVE-2020-27763?
Yes, there are known remedies available. Please refer to the provided references for more information on specific remedies.