A division-by-zero exception was found in ImageMagick in MagickCore/gem.c. An attacker can submit a crafted file to ImageMagick and trigger the division-by-zero exception. It most likely will lead to a DoS attack, but could also cause other problems related to undefined behavior. This bug affects ImageMagick versions prior to 7.0.11-2. Reference: https://github.com/ImageMagick/ImageMagick/issues/3321 Upstream patch: https://github.com/ImageMagick/ImageMagick/commit/c524ed20cf823088d725b3bdac80a717da10d592 https://github.com/ImageMagick/ImageMagick6/commit/64c0cc234280544dabacc2b28017521851deebde
Created ImageMagick tracking bugs for this issue: Affects: epel-8 [bug 1950845] Affects: fedora-all [bug 1950844]
Statement: Red Hat does not consider a division-by-zero in ImageMagick to be a security flaw