Do your applications use this vulnerable package?
Test your applications
Overview
Affected versions of this package are vulnerable to Integer Overflow or Wraparound. In ImageMagick, there is an outside the range of representable values of type 'unsigned int' at MagickCore/quantum-private.h. This flaw affects ImageMagick versions prior to 7.0.9-0.
Remediation
There is no fixed version for imagemagick
.
References
CVSS Score
3.3
low severity
-
Attack VectorLocal
-
Attack ComplexityLow
-
Privileges RequiredNone
-
User InteractionRequired
-
ScopeUnchanged
-
ConfidentialityNone
-
IntegrityNone
-
AvailabilityLow
- CVE
- CVE-2020-27768
- CWE
- CWE-190
- Snyk ID
- SNYK-DEBIAN10-IMAGEMAGICK-1045695
- Disclosed
- 23 Feb, 2021
- Published
- 26 Nov, 2020