Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2020-25675
Description:In the CropImage() and CropImageToTiles() routines of MagickCore/transform.c, rounding calculations performed on unconstrained pixel offsets was causing undefined behavior in the form of integer overflow and out-of-range values as reported by UndefinedBehaviorSanitizer. Such issues could cause a negative impact to application availability or other problems related to undefined behavior, in cases where ImageMagick processes untrusted input data. The upstream patch introduces functionality to constrain the pixel offsets and prevent these issues. This flaw affects ImageMagick versions prior to 7.0.9-0.
Test IDs: 1.3.6.1.4.1.25623.1.1.1.2.2023.3357  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2020-25675
https://bugzilla.redhat.com/show_bug.cgi?id=1891933
https://bugzilla.redhat.com/show_bug.cgi?id=1891933
https://lists.debian.org/debian-lts-announce/2021/03/msg00030.html
https://lists.debian.org/debian-lts-announce/2023/03/msg00008.html




© 1998-2025 E-Soft Inc. All rights reserved.