CVE-2020-25676

In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and InterpolatePixelInfo(), which are all functions in /MagickCore/pixel.c, there were multiple unconstrained pixel offset calculations which were being used with the floor() function. These calculations produced undefined behavior in the form of out-of-range and integer overflows, as identified by UndefinedBehaviorSanitizer. These instances of undefined behavior could be triggered by an attacker who is able to supply a crafted input file to be processed by ImageMagick. These issues could impact application availability or potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

History

11 Mar 2023, 23:15

Type Values Removed Values Added
CWE CWE-190
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2023/03/msg00008.html -

25 Mar 2021, 21:10

Type Values Removed Values Added
References (MLIST) https://lists.debian.org/debian-lts-announce/2021/03/msg00030.html - (MLIST) https://lists.debian.org/debian-lts-announce/2021/03/msg00030.html - Mailing List, Third Party Advisory
CPE cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

24 Mar 2021, 01:15

Type Values Removed Values Added
References
  • (MLIST) https://lists.debian.org/debian-lts-announce/2021/03/msg00030.html -

Information

Published : 2020-12-08 22:15

Updated : 2023-12-10 13:41


NVD link : CVE-2020-25676

Mitre link : CVE-2020-25676

CVE.ORG link : CVE-2020-25676


JSON object : View

Products Affected

debian

  • debian_linux

imagemagick

  • imagemagick
CWE
CWE-190

Integer Overflow or Wraparound