Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2020-27760

Published: 3 December 2020

In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero condition when a crafted input file is processed by ImageMagick. This could lead to an impact to application availability. The patch uses the `PerceptibleReciprocal()` to prevent the divide-by-zero from occurring. This flaw affects ImageMagick versions prior to ImageMagick 7.0.8-68.

Priority

Low

Cvss 3 Severity Score

5.5

Score breakdown

Status

Package Release Status
imagemagick
Launchpad, Ubuntu, Debian
impish Not vulnerable
(8:6.9.11.60+dfsg-1ubuntu1)
xenial
Released (8:6.8.9.9-7ubuntu5.16+esm2)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
kinetic Not vulnerable
(8:6.9.11.60+dfsg-1ubuntu1)
bionic
Released (8:6.9.7.4+dfsg-16ubuntu6.11)
focal
Released (8:6.9.10.23+dfsg-2.1ubuntu11.4)
groovy
Released (8:6.9.10.23+dfsg-2.1ubuntu13.3)
hirsute Not vulnerable
(8:6.9.11.60+dfsg-1ubuntu1)
jammy Not vulnerable
(8:6.9.11.60+dfsg-1ubuntu1)
lunar Not vulnerable
(8:6.9.11.60+dfsg-1ubuntu1)
trusty Needed

upstream
Released (8:6.9.11.24+dfsg-1)
Patches:
upstream: https://github.com/ImageMagick/ImageMagick6/commit/83cd04f580ccf4cc194813777c1fcfba78e602aa

Severity score breakdown

Parameter Value
Base score 5.5
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H