CVE-2020-27770: Integer Overflow
Due to a missing check for 0 value of replaceextent, it is possible for offset p to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered by a crafted input file that is processed by ImageMagick. This flaw affects ImageMagick versions prior to 7.0.8-68.
Other sources
In ImageMagick, there is an integer overflow in MagickCore/string.c.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1721
Upstream patch: https://github.com/ImageMagick/ImageMagick/commit/be90a5395695f0d19479a5d46b06c678be7f7927
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-27770?
CVE-2020-27770 is a vulnerability in ImageMagick that allows for offset overflow in SubstituteString(), potentially impacting application availability.
How severe is CVE-2020-27770?
CVE-2020-27770 has a severity score of 5.5, indicating a medium-level vulnerability.
Which software versions are affected by CVE-2020-27770?
ImageMagick versions prior to 8:6.9.7.4+dfsg-16ubuntu6.11, 8:6.9.10.23+dfsg-2.1ubuntu11.4, 8:6.9.10.23+dfsg-2.1ubuntu13.3, 8:6.9.11.24+dfsg-1, and 8:6.8.9.9-7ubuntu5.16+ are affected by CVE-2020-27770.
How can I fix CVE-2020-27770?
To fix CVE-2020-27770, it is recommended to update ImageMagick to version 8:6.9.7.4+dfsg-16ubuntu6.11, 8:6.9.10.23+dfsg-2.1ubuntu11.4, 8:6.9.10.23+dfsg-2.1ubuntu13.3, 8:6.9.11.24+dfsg-1, or 8:6.8.9.9-7ubuntu5.16+ depending on the version you are using.
Where can I find more information about CVE-2020-27770?
You can find more information about CVE-2020-27770 on the official CVE page: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27770