Integer Overflow or Wraparound Affecting imagemagick package, versions <8:6.9.10.23+dfsg-2.1+deb10u2
Snyk CVSS
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-DEBIAN10-IMAGEMAGICK-1045677
- published 26 Nov 2020
- disclosed 8 Dec 2020
Introduced: 26 Nov 2020
CVE-2020-25675 Open this link in a new tabHow to fix?
Upgrade Debian:10
imagemagick
to version 8:6.9.10.23+dfsg-2.1+deb10u2 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream imagemagick
package and not the imagemagick
package as distributed by Debian
.
See How to fix?
for Debian:10
relevant fixed versions and status.
In the CropImage() and CropImageToTiles() routines of MagickCore/transform.c, rounding calculations performed on unconstrained pixel offsets was causing undefined behavior in the form of integer overflow and out-of-range values as reported by UndefinedBehaviorSanitizer. Such issues could cause a negative impact to application availability or other problems related to undefined behavior, in cases where ImageMagick processes untrusted input data. The upstream patch introduces functionality to constrain the pixel offsets and prevent these issues. This flaw affects ImageMagick versions prior to 7.0.9-0.