CVE-2020-27764

LOW

Imagemagick < 6.9.10-69 - Integer Overflow

Title source: rule
STIX 2.1

Description

In /MagickCore/statistic.c, there are several areas in ApplyEvaluateOperator() where a size_t cast should have been a ssize_t cast, which causes out-of-range values under some circumstances when a crafted input file is processed by ImageMagick. Red Hat Product Security marked this as Low severity because although it could potentially lead to an impact to application availability, no specific impact was shown in this case. This flaw affects ImageMagick versions prior to 6.9.10-69.

Scores

CVSS v3 3.3
EPSS 0.0009
EPSS Percentile 26.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L

Details

CWE
CWE-190
Status published
Products (2)
debian/debian_linux 9.0
imagemagick/imagemagick < 6.9.10-69
Published Dec 03, 2020
Tracked Since Feb 18, 2026