A division-by-zero exception was found in ImageMagick in MagickCore/gem.c: ConvertRGBToHSV(). An attacker can submit a crafted file to ImageMagick and trigger the division-by-zero exception. It most likely will lead to a DoS attack, but could also cause other problems related to undefined behavior. This bug affects ImageMagick versions prior to 7.0.11-2. Reference: https://github.com/ImageMagick/ImageMagick/issues/3320 Upstream patch: https://github.com/ImageMagick/ImageMagick/commit/53ec59917b4da74cd4a46ea48f3d3a8fdf4adbde https://github.com/ImageMagick/ImageMagick6/commit/b3653027e9dc93d03917db602b83d15e70fee575
Created ImageMagick tracking bugs for this issue: Affects: epel-8 [bug 1950841]
Created ImageMagick tracking bugs for this issue: Affects: fedora-all [bug 1950842]
Statement: Red Hat does not consider a division-by-zero in ImageMagick to be a security flaw