CVE-2020-27776

NameCVE-2020-27776
DescriptionA flaw was found in ImageMagick in MagickCore/statistic.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type unsigned long. This would most likely lead to an impact to application availability, but could potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub code/issues, web search, more)
ReferencesDLA-2602-1
NVD severitymedium

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
imagemagick (PTS)stretch8:6.9.7.4+dfsg-11+deb9u8vulnerable
stretch (security)8:6.9.7.4+dfsg-11+deb9u13fixed
buster, buster (security)8:6.9.10.23+dfsg-2.1+deb10u1vulnerable
bookworm, sid, bullseye8:6.9.11.60+dfsg-1.3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
imagemagicksourcestretch8:6.9.7.4+dfsg-11+deb9u12DLA-2602-1
imagemagicksource(unstable)8:6.9.11.24+dfsg-1

Notes

[buster] - imagemagick <ignored> (Minor issue)
https://github.com/ImageMagick/ImageMagick/issues/1736
ImageMagick: https://github.com/ImageMagick/ImageMagick/commit/0c92913ec5705300943703f1795f34c0cc25164e
ImageMagick6: https://github.com/ImageMagick/ImageMagick6/commit/3e21bc8a58b4ae38d24c7e283837cc279f35b6a5

Search for package or bug name: Reporting problems