CVE-2021-20241
ImageMagick vulnerability analysis and mitigation

Overview

A flaw was discovered in ImageMagick's coders/jp2.c component (CVE-2021-20241), reported in February 2021. The vulnerability affects ImageMagick versions prior to 6.9.11-62 and 7.0.10-62. This security issue involves undefined behavior in the form of a division by zero operation in the WriteJP2Image() function (NVD, Red Hat Bugzilla).

Technical details

The vulnerability exists in the WriteJP2Image() function of the JP2 coder where a division by zero condition can occur because jp2_image->comps[i].dy could be set to zero when ImageMagick processes a crafted input file. The issue was addressed by implementing the PerceptibleReciprocal() routine instead of direct division in the computations. The vulnerability has a CVSS v3.1 Base Score of 5.5 (Medium) with the vector string CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H (NVD).

Impact

The primary impact of this vulnerability is to system availability. When exploited, the division by zero condition could lead to application crashes or other undefined behavior. While the highest threat is to system availability, the undefined behavior could potentially cause other unspecified impacts (Red Hat Bugzilla).

Exploitability

The vulnerability can be triggered by an attacker submitting a specially crafted file for processing by ImageMagick. The attack requires user interaction (opening a malicious file) but does not require special privileges. The attack complexity is considered low, indicating that the vulnerability is relatively straightforward to exploit (NVD).

Mitigation and workarounds

The vulnerability was fixed in ImageMagick versions 6.9.11-62 and 7.0.10-62. The fix involves using the PerceptibleReciprocal() routine instead of direct division in the computations. Various Linux distributions have released security updates to address this vulnerability, including Debian and Ubuntu (GitHub PR, Debian Advisory).

Additional resources


SourceThis report was generated using AI

Related ImageMagick vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-64685MEDIUM5.3
  • ImageMagick logoImageMagick
  • ImageMagick-c++
NoYesJul 30, 2026
CVE-2026-62363MEDIUM5
  • C# logoC#
  • seal-ImageMagick
NoYesJul 30, 2026
CVE-2026-66011MEDIUM4.8
  • ImageMagick logoImageMagick
  • perl-PerlMagick
NoYesJul 25, 2026
CVE-2026-62946MEDIUM4.7
  • C# logoC#
  • ImageMagick-config-7-upstream-open
NoYesJul 30, 2026
CVE-2026-62343MEDIUM4.7
  • C# logoC#
  • Magick.NET-Q8-OpenMP-arm64
NoYesJul 30, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management