CVE-2020-13902Out-of-bounds Read in Imagemagick

CWE-125Out-of-bounds Read6 documents6 sources
Severity
7.1HIGHNVD
EPSS
0.3%
top 48.75%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 7
Latest updateMay 24

Description

ImageMagick 7.0.9-27 through 7.0.10-17 has a heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c during TIFF image decoding.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages3 packages

debiandebian/imagemagick< imagemagick 8:6.9.11.24+dfsg-1 (bookworm)
Debianimagemagick/imagemagick< 8:6.9.11.24+dfsg-1+3
NVDimagemagick/imagemagick7.0.9-277.0.10-17

🔴Vulnerability Details

2
GHSA
GHSA-mg9m-6vj7-7v9f: ImageMagick 72022-05-24
OSV
CVE-2020-13902: ImageMagick 72020-06-07

📋Vendor Advisories

2
Red Hat
ImageMagick: heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c during TIFF image decoding2020-06-07
Debian
CVE-2020-13902: imagemagick - ImageMagick 7.0.9-27 through 7.0.10-17 has a heap-based buffer over-read in Blob...2020

💬Community

1
Bugzilla
CVE-2020-13902 ImageMagick: heap-based buffer over-read in BlobToStringInfo in MagickCore/string.c during TIFF image decoding2020-06-19