CVE-2020-10251Out-of-bounds Read in Imagemagick

CWE-125Out-of-bounds Read9 documents7 sources
Severity
5.5MEDIUMNVD
EPSS
0.5%
top 32.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10
Latest updateMay 24

Description

In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the ReadHEICImageByID function in coders\heic.c. It can be triggered via an image with a width or height value that exceeds the actual size of the image.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/imagemagick< imagemagick 8:6.9.11.24+dfsg-1 (bookworm)
Debianimagemagick/imagemagick< 8:6.9.11.24+dfsg-1+3

Patches

🔴Vulnerability Details

2
GHSA
GHSA-x22r-v7xh-wg93: In ImageMagick 72022-05-24
OSV
CVE-2020-10251: In ImageMagick 72020-03-10

📋Vendor Advisories

3
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Multimedia — CVE-2016-102512020-04-15
Red Hat
ImageMagick: out-of-bounds read in ReadHEICImageByID function in coders/heic.c2020-03-03
Debian
CVE-2020-10251: imagemagick - In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the Read...2020

💬Community

3
Bugzilla
CVE-2020-10251 ImageMagick: out-of-bounds read in ReadHEICImageByID function in coders/heic.c [epel-8]2020-03-13
Bugzilla
CVE-2020-10251 ImageMagick: out-of-bounds read in ReadHEICImageByID function in coders/heic.c [fedora-all]2020-03-13
Bugzilla
CVE-2020-10251 ImageMagick: out-of-bounds read in ReadHEICImageByID function in coders/heic.c2020-03-13