Lucene search

K
ubuntucveUbuntu.comUB:CVE-2021-20311
HistoryMay 11, 2021 - 12:00 a.m.

CVE-2021-20311

2021-05-1100:00:00
ubuntu.com
ubuntu.com
21
imagemagick
system availability
srgbtransformimage
crafted image
vulnerability

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

36.9%

A flaw was found in ImageMagick in versions before 7.0.11, where a division
by zero in sRGBTransformImage() in the MagickCore/colorspace.c may trigger
undefined behavior via a crafted image file that is submitted by an
attacker processed by an application using ImageMagick. The highest threat
from this vulnerability is to system availability.

Notes

Author Note
ebarretto Specific to ImageMagick version 7.

CVSS2

7.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:N/I:N/A:C

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS

0.001

Percentile

36.9%