CVE-2020-10251 — Out-of-bounds Read in Imagemagick
Severity
5.5MEDIUMNVD
EPSS
0.5%
top 32.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 10
Latest updateMay 24
Description
In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the ReadHEICImageByID function in coders\heic.c. It can be triggered via an image with a width or height value that exceeds the actual size of the image.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages3 packages
Patches
🔴Vulnerability Details
2📋Vendor Advisories
3Debian▶
CVE-2020-10251: imagemagick - In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the Read...↗2020
💬Community
3Bugzilla▶
CVE-2020-10251 ImageMagick: out-of-bounds read in ReadHEICImageByID function in coders/heic.c [epel-8]↗2020-03-13
Bugzilla▶
CVE-2020-10251 ImageMagick: out-of-bounds read in ReadHEICImageByID function in coders/heic.c [fedora-all]↗2020-03-13
Bugzilla▶
CVE-2020-10251 ImageMagick: out-of-bounds read in ReadHEICImageByID function in coders/heic.c↗2020-03-13