
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-27771 is a vulnerability discovered in ImageMagick's PDF handling functionality. The issue was identified in the RestoreMSCWarning() function of coders/pdf.c, where calls to GetPixelIndex() could result in values outside the range representable for the unsigned char type (Red Hat Bugzilla).
The vulnerability stems from several areas in the RestoreMSCWarning() function where calls to GetPixelIndex() could produce values outside the representable range for the unsigned char type. The issue was addressed by casting the return value of GetPixelIndex() to ssize_t type to avoid this undefined behavior (Red Hat Bugzilla).
Red Hat Product Security assessed this as a Low severity vulnerability because while it could potentially lead to an impact on application availability, no specific impact was demonstrated in this case (Red Hat Bugzilla).
The undefined behavior could be triggered when ImageMagick processes a crafted PDF file (Red Hat Bugzilla).
The vulnerability was fixed in ImageMagick version 7.0.9-0. Multiple distributions have released security updates to address this issue, including Ubuntu, Debian, and others. Users are recommended to upgrade their ImageMagick packages to the latest version (Ubuntu Security, Debian LTS).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."