First published: Mon Feb 15 2021(Updated: )
A flaw was found in ImageMagick in MagickCore/resample.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick ImageMagick | <6.9.11-62 | |
ImageMagick ImageMagick | >=7.0.0<7.0.10-62 | |
Redhat Enterprise Linux | =6.0 | |
Redhat Enterprise Linux | =7.0 | |
Redhat Enterprise Linux | =8.0 | |
Fedoraproject Fedora | =33 | |
Debian Debian Linux | =9.0 | |
redhat/ImageMagick 6.9.11 | <62 | 62 |
redhat/ImageMagick 7.0.10 | <62 | 62 |
debian/imagemagick | 8:6.9.11.60+dfsg-1.3+deb11u4 8:6.9.11.60+dfsg-1.3+deb11u3 8:6.9.11.60+dfsg-1.6+deb12u2 8:6.9.11.60+dfsg-1.6+deb12u1 8:7.1.1.43+dfsg1-1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-20246 is a vulnerability found in ImageMagick that could trigger undefined behavior in the form of math division by zero.
CVE-2021-20246 poses a high threat to system availability.
CVE-2021-20246 affects ImageMagick versions 8:6.9.7.4+dfsg-16ubuntu6.12, 8:6.7.7.10-6ubuntu3.13+, 8:6.8.9.9-7ubuntu5.16+, 8:6.9.10.23+dfsg-2.1ubuntu11.9, 8:6.9.11.60+dfsg-1.3ubuntu1, 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+, 8:6.9.11.60+dfsg-1.3ubuntu0.22.10.1, 8:6.9.11.60+dfsg-1.3ubuntu1, and 8:6.9.10.23+dfsg-2.1+deb10u5, 8:6.9.11.60+dfsg-1.6.
To fix CVE-2021-20246, you should update ImageMagick to versions 8:6.9.7.4+dfsg-16ubuntu6.12, 8:6.7.7.10-6ubuntu3.13+, 8:6.8.9.9-7ubuntu5.16+, 8:6.9.10.23+dfsg-2.1ubuntu11.9, 8:6.9.11.60+dfsg-1.3ubuntu1, 8:6.9.11.60+dfsg-1.3ubuntu0.22.04.3+, 8:6.9.11.60+dfsg-1.3ubuntu0.22.10.1, 8:6.9.11.60+dfsg-1.3ubuntu1, 8:6.9.10.23+dfsg-2.1+deb10u5, or 8:6.9.11.60+dfsg-1.6.
You can find more information about CVE-2021-20246 on the following links: [link1], [link2], [link3].