CVE-2020-27763

MEDIUM

Description

A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.8-68.

References

https://bugzilla.redhat.com/show_bug.cgi?id=1894682

https://lists.debian.org/debian-lts-announce/2021/01/msg00010.html

Details

Source: MITRE

Published: 2020-12-03

Updated: 2021-02-24

Type: CWE-369

Risk Information

CVSS v2.0

Base Score: 4.3

Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Impact Score: 2.9

Exploitability Score: 8.6

Severity: MEDIUM

CVSS v3.0

Base Score: 3.3

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Impact Score: 1.4

Exploitability Score: 1.8

Severity: LOW

Tenable Plugins

View all (6 total)

IDNameProductFamilySeverity
145394openSUSE Security Update : ImageMagick (openSUSE-2021-148)NessusSuSE Local Security Checks
medium
145363SUSE SLES12 Security Update : ImageMagick (SUSE-SU-2021:0199-1)NessusSuSE Local Security Checks
medium
145361openSUSE Security Update : ImageMagick (openSUSE-2021-136)NessusSuSE Local Security Checks
medium
145198SUSE SLED15 / SLES15 Security Update : ImageMagick (SUSE-SU-2021:0153-1)NessusSuSE Local Security Checks
medium
145181SUSE SLED15 / SLES15 Security Update : ImageMagick (SUSE-SU-2021:0156-1)NessusSuSE Local Security Checks
medium
144925Debian DLA-2523-1 : imagemagick security updateNessusDebian Local Security Checks
medium