First published: Wed Nov 04 2020(Updated: )
In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h. Reference: <a href="https://github.com/ImageMagick/ImageMagick/issues/1751">https://github.com/ImageMagick/ImageMagick/issues/1751</a> Upstream patch: <a href="https://github.com/ImageMagick/ImageMagick/commit/95d4e94e0353e503b71a53f5e6fad173c7c70c90">https://github.com/ImageMagick/ImageMagick/commit/95d4e94e0353e503b71a53f5e6fad173c7c70c90</a>
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | <7.0.9-0 | |
Debian Debian Linux | =9.0 | |
redhat/ImageMagick 7.0.9 | <0 | 0 |
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u4 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u2 8:6.9.11.60+dfsg-1.6+deb12u1 8:7.1.1.39+dfsg1-3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this ImageMagick vulnerability is CVE-2020-27768.
The severity of CVE-2020-27768 is medium with a severity value of 3.3.
ImageMagick versions prior to 7.0.9-0 are affected by CVE-2020-27768.
To fix CVE-2020-27768 on Ubuntu, update ImageMagick to version 8:6.9.7.4+dfsg-16ubuntu6.11 or later.
You can find more information about CVE-2020-27768 at the following references: - [CVE Mitre](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27768) - [Ubuntu Security Notice](https://ubuntu.com/security/notices/USN-4988-1) - [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-27768)