CVE Database
/

CVE-2020-27770

Back to search

CVE-2020-27770

Published: Dec 4, 2020

Modified: Aug 4, 2024

PUBLISHED

Description

Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered by a crafted input file that is processed by ImageMagick. This flaw affects ImageMagick versions prior to 7.0.8-68.

VendorProductVersions

n/a

ImageMagick

affected
ImageMagick 7.0.8-68

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now