CVE-2020-27752

Name
CVE-2020-27752
Description
A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to application availability, but could potentially lead to an impact to data integrity as well. This flaw affects ImageMagick versions prior to 7.0.9-0.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Exploit https://bugzilla.redhat.com/show_bug.cgi?id=1894226

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* imagemagick >= None < 7.0.9-0
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* imagemagick >= None < 6.9.11-47
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* imagemagick >= 7.0.0-0 < 7.0.9-0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
imagemagick 3.10-main 7.0.8.68-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable