Lucene search

K
osvGoogleOSV:CVE-2020-27770
HistoryDec 04, 2020 - 3:15 p.m.

CVE-2020-27770

2020-12-0415:15:10
Google
osv.dev
6
imagemagick
substitutestring
offset overflow
application availability
cve-2020-27770

AI Score

6.5

Confidence

Low

EPSS

0.001

Percentile

34.6%

Due to a missing check for 0 value of replace_extent, it is possible for offset p to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered by a crafted input file that is processed by ImageMagick. This flaw affects ImageMagick versions prior to 7.0.8-68.