Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-25664
Description:In WriteOnePNGImage() of the PNG coder at coders/png.c, an improper call to AcquireVirtualMemory() and memset() allows for an out-of- bounds write later when PopShortPixel() from MagickCore/quantum- private.h is called. The patch fixes the calls by adding 256 to rowbytes. An attacker who is able to supply a specially crafted image could affect availability with a low impact to data integrity. This flaw affects ImageMagick versions prior to 6.9.10-68 and 7.0.8-68.
Test IDs: 1.3.6.1.4.1.25623.1.0.819339   1.3.6.1.4.1.25623.1.0.819331   1.3.6.1.4.1.25623.1.0.819352   1.3.6.1.4.1.25623.1.0.819355   1.3.6.1.4.1.25623.1.0.819424   1.3.6.1.4.1.25623.1.0.819415   1.3.6.1.4.1.25623.1.0.819383   1.3.6.1.4.1.25623.1.0.819379   1.3.6.1.4.1.25623.1.0.819322   1.3.6.1.4.1.25623.1.0.819328   1.3.6.1.4.1.25623.1.0.819375   1.3.6.1.4.1.25623.1.0.819320   1.3.6.1.4.1.25623.1.0.819327   1.3.6.1.4.1.25623.1.0.819305   1.3.6.1.4.1.25623.1.0.819309   1.3.6.1.4.1.25623.1.0.819416   1.3.6.1.4.1.25623.1.0.819304   1.3.6.1.4.1.25623.1.0.819361   1.3.6.1.4.1.25623.1.0.819321   1.3.6.1.4.1.25623.1.0.819332   1.3.6.1.4.1.25623.1.0.819396   1.3.6.1.4.1.25623.1.0.819349   1.3.6.1.4.1.25623.1.0.819420   1.3.6.1.4.1.25623.1.0.819406  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-25664
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Z3J6D7POCQYQKNVRDYLTTPM5SQC3WVTR/
https://bugzilla.redhat.com/show_bug.cgi?id=1891605
https://bugzilla.redhat.com/show_bug.cgi?id=1891605




© 1998-2025 E-Soft Inc. All rights reserved.