CVE-2020-27772: Integer Overflow
A flaw was found in ImageMagick in coders/bmp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned int. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.
Other sources
In ImageMagick, there are 9 outside the range of representable values of type 'unsigned int' at coders/bmp.c.
Reference: https://github.com/ImageMagick/ImageMagick/issues/1749
Upstream patch: https://github.com/ImageMagick/ImageMagick/commit/a1142af44f61c038ad3eccc099c5b9548b507846
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-27772?
CVE-2020-27772 is a vulnerability found in ImageMagick in coders/bmp.c.
What is the severity of CVE-2020-27772?
The severity of CVE-2020-27772 is medium, with a severity value of 3.3.
How does CVE-2020-27772 impact application availability?
CVE-2020-27772 can lead to an impact on application availability.
How can I fix CVE-2020-27772?
To fix CVE-2020-27772, update ImageMagick to version 8:6.9.10.23+dfsg-2.1ubuntu13.3.
Where can I find more information about CVE-2020-27772?
You can find more information about CVE-2020-27772 at the following references: CVE-2020-27772, Ubuntu Security Notice USN-4988-1, and NIST NVD CVE-2020-27772.