
Cloud Vulnerability DB
A community-led vulnerabilities database
A flaw was discovered in ImageMagick's MagickCore/quantum.h that could trigger undefined behavior in the form of values outside the range of types 'float' and 'unsigned char'. This vulnerability, identified as CVE-2020-27767, affects ImageMagick versions prior to 7.0.9-0 (NVD, Red Hat Bugzilla).
The vulnerability has been assigned a CVSS v3.1 Base Score of 3.3 (LOW) with the vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L. The issue stems from improper handling of values in the MagickCore/quantum.h file, where certain operations could lead to values falling outside the representable range for 'float' and 'unsigned char' data types (NVD).
The primary impact of this vulnerability is to application availability, though other unspecified problems related to undefined behavior could potentially occur. When an attacker submits a crafted file that is processed by ImageMagick, it could trigger the undefined behavior, most likely resulting in application crashes (Red Hat Bugzilla).
The vulnerability requires local access and user interaction to exploit, as indicated by the CVSS vector. An attacker would need to submit a specially crafted file for processing by ImageMagick to trigger the undefined behavior (NVD).
The vulnerability has been fixed in ImageMagick version 7.0.9-0. Various Linux distributions have also released patches for their respective versions, including Debian with version 8:6.9.7.4+dfsg-11+deb9u12 for Stretch and 8:6.9.10.23+dfsg-2.1+deb10u2 for Buster (Debian LTS, Debian LTS 2023).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."