CVE-2021-20224: Integer Overflow
An integer overflow issue was discovered in ImageMagick's ExportIndexQuantum() function in MagickCore/quantum-export.c. Function calls to GetPixelIndex() could result in values outside the range of representable for the 'unsigned char'. When ImageMagick processes a crafted pdf file, this could lead to an undefined behaviour or a crash.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20224?
The severity of CVE-2021-20224 is medium.
How does CVE-2021-20224 affect ImageMagick?
CVE-2021-20224 affects ImageMagick's ExportIndexQuantum() function in MagickCore/quantum-export.c.
What is the impact of CVE-2021-20224?
The impact of CVE-2021-20224 is an integer overflow issue which could lead to values outside the range of representable for the 'unsigned char' when processing a crafted pdf file.
Which versions of ImageMagick are affected by CVE-2021-20224?
ImageMagick versions 8:6.9.10.23+dfsg-2.1ubuntu11.9, 8:6.9.7.4+dfsg-16ubuntu6.14, 8:6.7.7.10-6ubuntu3.13+, 8:6.9.11.57+dfsg-1, and 8:6.8.9.9-7ubuntu5.16+ are affected by CVE-2021-20224.
How can I fix CVE-2021-20224 in ImageMagick?
To fix CVE-2021-20224 in ImageMagick, update to the recommended versions: 8:6.9.10.23+dfsg-2.1ubuntu11.9, 8:6.9.7.4+dfsg-16ubuntu6.14, 8:6.7.7.10-6ubuntu3.13+, 8:6.9.11.57+dfsg-1, or 8:6.8.9.9-7ubuntu5.16+.