Bug 1922525 (CVE-2020-27829) - CVE-2020-27829 ImageMagick: heap buffer overflow in coders/tiff.c
Summary: CVE-2020-27829 ImageMagick: heap buffer overflow in coders/tiff.c
Keywords:
Status: CLOSED WONTFIX
Alias: CVE-2020-27829
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1922526 1922528 1924790
Blocks: 1922527 1939991
TreeView+ depends on / blocked
 
Reported: 2021-01-30 00:48 UTC by Pedro Sampaio
Modified: 2021-10-28 10:38 UTC (History)
5 users (show)

Fixed In Version: ImageMagick 7.0.10-45
Doc Type: If docs needed, set a value
Doc Text:
A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service.
Clone Of:
Environment:
Last Closed: 2021-10-28 10:38:20 UTC
Embargoed:


Attachments (Terms of Use)

Description Pedro Sampaio 2021-01-30 00:48:35 UTC
A flaw was found in ImageMagick 7.0.10-45. A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service.

Upstream patch:

https://github.com/ImageMagick/ImageMagick/commit/6ee5059cd3ac8d82714a1ab1321399b88539abf0

Comment 1 Pedro Sampaio 2021-01-30 00:49:10 UTC
Created ImageMagick tracking bugs for this issue:

Affects: epel-8 [bug 1922526]
Affects: fedora-all [bug 1922528]


Note You need to log in before you can comment on or make changes to this bug.