A division-by-zero exception was found in ImageMagick in MagickCore/distort.c: DistortImage(). An attacker can submit a crafted file to ImageMagick and trigger the division-by-zero exception. It most likely will lead to a DoS attack affecting servers' availability, but could also cause other problems related to undefined behavior. This bug affects ImageMagick versions prior to 7.0.11-2 (included). Reference: https://github.com/ImageMagick/ImageMagick/issues/3331 Upstream patch: https://github.com/ImageMagick/ImageMagick6/commit/4eafab89a2742865d770857a9d7434993f65ae6b https://github.com/ImageMagick/ImageMagick/commit/f8e8535bc821f24a30beee0030ff21ee3a2deedc
Created ImageMagick tracking bugs for this issue: Affects: epel-8 [bug 1950871] Affects: fedora-all [bug 1950870]
Statement: Red Hat does not consider a division-by-zero in ImageMagick to be a security flaw