CVE-2020-27764
ImageMagick vulnerability analysis and mitigation

Overview

CVE-2020-27764 is a vulnerability discovered in ImageMagick affecting versions prior to 6.9.10-69. The issue exists in /MagickCore/statistic.c, where several areas in ApplyEvaluateOperator() contain incorrect type casting from size_t to ssize_t, which can lead to out-of-range values when processing crafted input files (NVD, Red Hat).

Technical details

The vulnerability stems from improper type casting in the ApplyEvaluateOperator() function within MagickCore/statistic.c. The issue involves several operations where size_t casts should have been ssize_t casts, potentially leading to undefined behavior. The vulnerability has been assigned a CVSS v3.1 base score of 3.3 (Low) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L, indicating local access is required and user interaction is needed (NVD).

Impact

The vulnerability's impact is primarily focused on application availability. While it could potentially lead to undefined behavior when processing crafted input files, Red Hat Product Security marked this as Low severity as no specific severe impact was demonstrated in this case (Red Hat).

Exploitability

The vulnerability requires local access and user interaction to exploit. An attacker would need to submit a crafted file that is processed by ImageMagick to trigger the undefined behavior related to out-of-range values (NVD).

Mitigation and workarounds

The vulnerability has been fixed in ImageMagick version 6.9.10-69. The fix involves correcting the type casting from size_t to ssize_t in the ApplyEvaluateOperator() function. A patch has been provided in the upstream repository (ImageMagick Patch).

Additional resources


SourceThis report was generated using AI

Related ImageMagick vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64685MEDIUM5.3
  • ImageMagick logoImageMagick
  • libMagick++-7_Q16HDRI5
NoYesJul 30, 2026
CVE-2026-62363MEDIUM5
  • C# logoC#
  • ImageMagick-config-7-upstream-limited
NoYesJul 30, 2026
CVE-2026-66011MEDIUM4.8
  • ImageMagick logoImageMagick
  • ImageMagick-devel
NoYesJul 25, 2026
CVE-2026-62946MEDIUM4.7
  • C# logoC#
  • libMagick++-devel
NoYesJul 30, 2026
CVE-2026-62343MEDIUM4.7
  • C# logoC#
  • Magick.NET-Q8-x86
NoYesJul 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management