CVE-2020-27769
published 2021-05-14CVE-2020-27769: In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.
PriorityP410low3.3CVSS 3.1
AVLACLPRNUIRSUCNINAL
EPSS
1.06%
61.0th percentile
In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.9.11.24+dfsg-1 (bookworm) | imagemagick 8:6.9.11.24+dfsg-1 (bookworm) |
| fedoraproject | fedora | — | — |
| imagemagick | imagemagick | < 7.0.9-0 | 7.0.9-0 |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.24+dfsg-1 | 8:6.9.11.24+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.24+dfsg-1 | 8:6.9.11.24+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.24+dfsg-1 | 8:6.9.11.24+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.24+dfsg-1 | 8:6.9.11.24+dfsg-1 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5q3f-hrrv-3qfw: In ImageMagick versions before 7
ghsa_unreviewed·2022-05-24
CVE-2020-27769 [MEDIUM] CWE-190 GHSA-5q3f-hrrv-3qfw: In ImageMagick versions before 7
In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.
OSV
CVE-2020-27769: In ImageMagick versions before 7
osv·2021-05-14·CVSS 3.3
CVE-2020-27769 [LOW] CVE-2020-27769: In ImageMagick versions before 7
In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2024-10-15
CVE-2019-7398 ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled certain
malformed image files. If a user or automated system using ImageMagick
were tricked into processing a specially crafted file, an attacker could
exploit this to cause a denial of service or affect the reliability of the
system. The vulnerabilities included memory leaks, buffer overflows, and
improper handling of pixel data.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
ImageMagick vulnerabilities
vendor_ubuntu·2021-06-15
CVE-2020-27757 ImageMagick vulnerabilities
Title: ImageMagick vulnerabilities
Summary: Several security issues were fixed in ImageMagick.
It was discovered that ImageMagick incorrectly handled certain malformed
image files. If a user or automated system using ImageMagick were tricked
into opening a specially crafted image, an attacker could exploit this to
cause a denial of service or possibly execute code with the privileges of
the user invoking the program.
Instructions: In general, a standard system update will make all the necessary changes.
Debian
CVE-2020-27769: imagemagick - In ImageMagick versions before 7.0.9-0, there are outside the range of represent...
vendor_debian·2020·CVSS 3.3
CVE-2020-27769 [LOW] CVE-2020-27769: imagemagick - In ImageMagick versions before 7.0.9-0, there are outside the range of represent...
In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1)
forky: resolved (fixed in 8:6.9.11.24+dfsg-1)
sid: resolved (fixed in 8:6.9.11.24+dfsg-1)
trixie: resolved (fixed in 8:6.9.11.24+dfsg-1)
Red Hat
ImageMagick: outside the range of representable values of type 'float' at MagickCore/quantize.c
vendor_redhat·2019-10-10·CVSS 3.3
CVE-2020-27769 [LOW] CWE-190 ImageMagick: outside the range of representable values of type 'float' at MagickCore/quantize.c
ImageMagick: outside the range of representable values of type 'float' at MagickCore/quantize.c
In ImageMagick versions before 7.0.9-0, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.
In ImageMagick, there are outside the range of representable values of type 'float' at MagickCore/quantize.c.
Statement: This flaw is out of support scope for Red Hat Enterprise Linux 5, 6, and 7. Inkscape is not affected because it no longer uses a bundled ImageMagick in Red Hat Enterprise Linux 8. For more information regarding support scopes, please see https://access.redhat.com/support/policy/updates/errata .
Package: ImageMagick (Red Hat Enterprise Linux 5) - Out of support scope
Package: ImageMagick (Red Hat Enterprise Linux 6) - Out of support scope
P
No detection rules found.
No public exploits indexed.
2021-05-14
Published