CVE Database
/

CVE-2021-20224

Back to search

CVE-2021-20224

Published: Aug 25, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

An integer overflow issue was discovered in ImageMagick's ExportIndexQuantum() function in MagickCore/quantum-export.c. Function calls to GetPixelIndex() could result in values outside the range of representable for the 'unsigned char'. When ImageMagick processes a crafted pdf file, this could lead to an undefined behaviour or a crash.

VendorProductVersions

n/a

ImageMagick

affected
Fixed in ImageMagick-7.0.10-57, ImageMagick6-6.9.11-57

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now