CVE-2020-27752

HIGH

Imagemagick < 6.9.11-47 - Heap Buffer Overflow

Title source: rule
STIX 2.1

Description

A flaw was found in ImageMagick in MagickCore/quantum-private.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger a heap buffer overflow. This would most likely lead to an impact to application availability, but could potentially lead to an impact to data integrity as well. This flaw affects ImageMagick versions prior to 7.0.9-0.

References (1)

Core 1
Core References
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=1894226

Scores

CVSS v3 7.1
EPSS 0.0032
EPSS Percentile 55.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H

Details

CWE
CWE-122
Status published
Products (1)
imagemagick/imagemagick < 6.9.11-47
Published Dec 08, 2020
Tracked Since Feb 18, 2026