CVE-2020-27767: Integer Overflow
A flaw was found in ImageMagick in MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of types float and unsigned char. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.
Other sources
In ImageMagick, there are an outside the range of representable values of type 'float' at MagickCore/quantum.h:87 and outside the range of representable values of type 'unsigned char' at MagickCore/quantum.h.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1741
Upstream patch: https://github.com/ImageMagick/ImageMagick/commit/564f2a35e523e2b6cce9485018157f03ec05a947
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-27767?
CVE-2020-27767 is a vulnerability found in ImageMagick in MagickCore/quantum.h that allows an attacker to trigger undefined behavior.
How does CVE-2020-27767 impact ImageMagick?
CVE-2020-27767 can lead to values outside the range of types `float` and `unsigned char`, causing potential impact to ImageMagick.
What is the severity of CVE-2020-27767?
CVE-2020-27767 has a severity rating of medium (3.3).
Which versions of ImageMagick are affected by CVE-2020-27767?
ImageMagick versions 8:6.9.10.23+dfsg-2.1ubuntu11.4, 8:6.9.10.23+dfsg-2.1ubuntu13.3, 8:6.9.11.24+dfsg-1, and 8:6.9.7.4+dfsg-16ubuntu6.11 are affected by CVE-2020-27767.
How can I fix CVE-2020-27767 in ImageMagick?
To fix CVE-2020-27767, update ImageMagick to versions 8:6.9.10.23+dfsg-2.1ubuntu11.4, 8:6.9.10.23+dfsg-2.1ubuntu13.3, 8:6.9.11.24+dfsg-1, or 8:6.9.7.4+dfsg-16ubuntu6.11.