Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-20224
HistoryAug 25, 2022 - 12:00 a.m.

CVE-2021-20224

2022-08-2500:00:00
ubuntu.com
ubuntu.com
25
imagemagick
exportindexquantum
integer overflow
pdf
crash
unix

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

29.4%

An integer overflow issue was discovered in ImageMagick’s
ExportIndexQuantum() function in MagickCore/quantum-export.c. Function
calls to GetPixelIndex() could result in values outside the range of
representable for the ‘unsigned char’. When ImageMagick processes a crafted
pdf file, this could lead to an undefined behaviour or a crash.

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchimagemagick< 8:6.9.7.4+dfsg-16ubuntu6.14UNKNOWN
ubuntu20.04noarchimagemagick< 8:6.9.10.23+dfsg-2.1ubuntu11.9UNKNOWN
ubuntu14.04noarchimagemagick< 8:6.7.7.10-6ubuntu3.13+esm3UNKNOWN
ubuntu16.04noarchimagemagick< 8:6.8.9.9-7ubuntu5.16+esm5UNKNOWN

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

29.4%