CVE-2020-27768: Integer Overflow
In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1751
Upstream patch: https://github.com/ImageMagick/ImageMagick/commit/95d4e94e0353e503b71a53f5e6fad173c7c70c90
Other sources
In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h. This flaw affects ImageMagick versions prior to 7.0.9-0.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this ImageMagick vulnerability?
The vulnerability ID for this ImageMagick vulnerability is CVE-2020-27768.
What is the severity of CVE-2020-27768?
The severity of CVE-2020-27768 is medium with a severity value of 3.3.
Which versions of ImageMagick are affected by CVE-2020-27768?
ImageMagick versions prior to 7.0.9-0 are affected by CVE-2020-27768.
How can I fix CVE-2020-27768 on Ubuntu?
To fix CVE-2020-27768 on Ubuntu, update ImageMagick to version 8:6.9.7.4+dfsg-16ubuntu6.11 or later.
Where can I find more information about CVE-2020-27768?
You can find more information about CVE-2020-27768 at the following references: - [CVE Mitre](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27768) - [Ubuntu Security Notice](https://ubuntu.com/security/notices/USN-4988-1) - [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-27768)