Lucene search

K
cveRedhatCVE-2021-20224
HistoryAug 25, 2022 - 8:15 p.m.

CVE-2021-20224

2022-08-2520:15:08
CWE-190
redhat
web.nvd.nist.gov
68
11
cve-2021-20224
imagemagick
integer overflow
exportindexquantum()
magickcore
nvd
security
vulnerability
pdf
getpixelindex()

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

29.4%

An integer overflow issue was discovered in ImageMagick’s ExportIndexQuantum() function in MagickCore/quantum-export.c. Function calls to GetPixelIndex() could result in values outside the range of representable for the ‘unsigned char’. When ImageMagick processes a crafted pdf file, this could lead to an undefined behaviour or a crash.

Affected configurations

Nvd
Vulners
Node
imagemagickimagemagickRange<6.9.11-57
OR
imagemagickimagemagickRange7.0.0-07.0.10-57
VendorProductVersionCPE
imagemagickimagemagick*cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "vendor": "n/a",
    "product": "ImageMagick",
    "versions": [
      {
        "version": "Fixed in ImageMagick-7.0.10-57, ImageMagick6-6.9.11-57",
        "status": "affected"
      }
    ]
  }
]

Social References

More

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

6.2

Confidence

High

EPSS

0.001

Percentile

29.4%