CVE-2020-27752
published 2020-12-08CVE-2020-27752: A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap…
PriorityP433high7.1CVSS 3.1
AVNACLPRNUIRSUCNILAH
EPSS
1.07%
61.4th percentile
A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to application availability, but could potentially lead to an impact to data integrity as well. This flaw affects ImageMagick versions prior to 7.0.9-0.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.9.11.24+dfsg-1 (bookworm) | imagemagick 8:6.9.11.24+dfsg-1 (bookworm) |
| imagemagick | imagemagick | < 6.9.11-47 | 6.9.11-47 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.24+dfsg-1 | 8:6.9.11.24+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.24+dfsg-1 | 8:6.9.11.24+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.24+dfsg-1 | 8:6.9.11.24+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.24+dfsg-1 | 8:6.9.11.24+dfsg-1 |
| imagemagick | imagemagick | >= 7.0.0-0 < 7.0.9-0 | 7.0.9-0 |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8h84-r7fq-5pcm: A flaw was found in ImageMagick in MagickCore/quantum-private
ghsa_unreviewed·2022-05-24
CVE-2020-27752 [MEDIUM] CWE-787 GHSA-8h84-r7fq-5pcm: A flaw was found in ImageMagick in MagickCore/quantum-private
A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to application availability, but could potentially lead to an impact to data integrity as well. This flaw affects ImageMagick versions prior to 7.0.9-0.
OSV
CVE-2020-27752: A flaw was found in ImageMagick in MagickCore/quantum-private
osv·2020-12-08·CVSS 7.1
CVE-2020-27752 [HIGH] CVE-2020-27752: A flaw was found in ImageMagick in MagickCore/quantum-private
A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to application availability, but could potentially lead to an impact to data integrity as well. This flaw affects ImageMagick versions prior to 7.0.9-0.
Debian
CVE-2020-27752: imagemagick - A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who...
vendor_debian·2020·CVSS 7.1
CVE-2020-27752 [HIGH] CVE-2020-27752: imagemagick - A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who...
A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to application availability, but could potentially lead to an impact to data integrity as well. This flaw affects ImageMagick versions prior to 7.0.9-0.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1)
forky: resolved (fixed in 8:6.9.11.24+dfsg-1)
sid: resolved (fixed in 8:6.9.11.24+dfsg-1)
trixie: resolved (fixed in 8:6.9.11.24+dfsg-1)
Red Hat
ImageMagick: heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h
vendor_redhat·2019-10-04·CVSS 7.1
CVE-2020-27752 [HIGH] CWE-122 ImageMagick: heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h
ImageMagick: heap-based buffer overflow in PopShortPixel in MagickCore/quantum-private.h
A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to application availability, but could potentially lead to an impact to data integrity as well. This flaw affects ImageMagick versions prior to 7.0.9-0.
A flaw was found in ImageMagick in MagickCore/quantum-private.h. This flaw allows an attacker who submits a crafted file processed by ImageMagick to trigger a heap buffer overflow. The highest threat from this vulnerability is to system availability and also a potential impact on data integrity.
Statement: This flaw is out of support sco
No detection rules found.
No public exploits indexed.
2020-12-08
Published