CVE-2021-20241: Divide by Zero
A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
Other sources
A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.10-62.
References:
https://github.com/ImageMagick/ImageMagick/pull/3177
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-20241?
CVE-2021-20241 is a vulnerability found in ImageMagick that allows an attacker to trigger undefined behavior through math division by zero.
What is the severity of CVE-2021-20241?
CVE-2021-20241 has a severity rating of 5.5 (medium severity).
How does CVE-2021-20241 affect ImageMagick?
CVE-2021-20241 affects ImageMagick versions 8:6.9.7.4+dfsg-16ubuntu6.14, 8:6.9.10.23+dfsg-2.1ubuntu11.9, 8:6.9.11.60+dfsg-1.3ubuntu0.22.10.1, 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+, 8:6.9.11.60+dfsg-1.3ubuntu1, and 8:6.8.9.9-7ubuntu5.16+ on Ubuntu, and versions 8:6.9.10.23+dfsg-2.1+deb10u5 and 8:6.9.11.60+dfsg-1.6 on Debian.
How can I fix CVE-2021-20241 on Ubuntu?
To fix CVE-2021-20241 on Ubuntu, update ImageMagick to versions 8:6.9.7.4+dfsg-16ubuntu6.14, 8:6.9.10.23+dfsg-2.1ubuntu11.9, 8:6.9.11.60+dfsg-1.3ubuntu0.22.10.1, 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+, or 8:6.9.11.60+dfsg-1.3ubuntu1.
How can I fix CVE-2021-20241 on Debian?
To fix CVE-2021-20241 on Debian, update ImageMagick to versions 8:6.9.10.23+dfsg-2.1+deb10u5 or 8:6.9.11.60+dfsg-1.6.