---
title: "CVE-2020-27751\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2020-27751?format=md
keywords: index, follow
---

# CVE-2020-27751

Publication date 8 December 2020

Last updated 18 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**3.3 · Low**

[Score breakdown](https://ubuntu.com/security/CVE-2020-27751?format=md#impact-score)

Toggle side navigation

## Description

A flaw was found in ImageMagick in MagickCore/quantum-export.c. An attacker
who submits a crafted file that is processed by ImageMagick could trigger
undefined behavior in the form of values outside the range of type
`unsigned long long` as well as a shift exponent that is too large for
64-bit type. This would most likely lead to an impact to application
availability, but could potentially cause other problems related to
undefined behavior. This flaw affects ImageMagick versions prior to
7.0.9-0.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| imagemagick | 26.04 LTS resolute | Not affected |
| 25.10 questing | Not affected |
| 25.04 plucky | Not affected |
| 24.10 oracular | Not affected |
| 24.04 LTS noble | Not affected |
| 23.10 mantic | Not affected |
| 23.04 lunar | Not affected |
| 22.10 kinetic | Not affected |
| 22.04 LTS jammy | Not affected |
| 21.10 impish | Not affected |
| 21.04 hirsute | Not affected |
| 20.10 groovy | Fixed 8:6.9.10.23+dfsg-2.1ubuntu13.3 |
| 20.04 LTS focal | Fixed 8:6.9.10.23+dfsg-2.1ubuntu11.4 |
| 18.04 LTS bionic | Fixed 8:6.9.7.4+dfsg-16ubuntu6.11 |
| 16.04 LTS xenial | Vulnerable |
| 14.04 LTS trusty | Vulnerable |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2020-27751?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| imagemagick | * Upstream:   [879bb6a](https://github.com/ImageMagick/ImageMagick6/commit/879bb6a13ece5508cd983bc3d64ced23900b60ee) |

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

3.3 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | Low |
  | Privileges required | None |
  | User interaction | Required |
  | Scope | Unchanged |
  | Confidentiality impact | None |
  | Integrity impact | None |
  | Availability impact | Low |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 3.3 · Low |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27751)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-27751)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2020-27751)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2020-27751)

### Related Ubuntu Security Notices (USN)

+ [USN-4988-1](https://usn.ubuntu.com/USN-4988-1)
+ ImageMagick vulnerabilities
+ 15 June 2021

### Other references

* <https://www.cve.org/CVERecord?id=CVE-2020-27751>
