CVE-2020-27761 — Integer Overflow or Wraparound in Imagemagick
Severity
3.3LOWNVD
EPSS
0.1%
top 68.02%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 3
Latest updateOct 15
Description
WritePALMImage() in /coders/palm.c used size_t casts in several areas of a calculation which could lead to values outside the range of representable type `unsigned long` undefined behavior when a crafted input file was processed by ImageMagick. The patch casts to `ssize_t` instead to avoid this issue. Red Hat Product Security marked the Severity as Low because although it could potentially lead to an impact to application availability, no specific impact was shown in this case. This flaw affects…
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:LExploitability: 1.8 | Impact: 1.4
Affected Packages4 packages
Also affects: Debian Linux 9.0
Patches
🔴Vulnerability Details
2📋Vendor Advisories
4💬Community
1Bugzilla▶
CVE-2020-27761 ImageMagick: outside the range of representable values of type 'unsigned long' at coders/palm.c↗2020-11-04