CVE-2020-27760 PUBLISHED

In `GammaImage()` of /MagickCore/enhance.c, depending on the `gamma` value, it's possible to trigger a divide-by-zero condition when a crafted input file is processed by ImageMagick. This could lead to an impact to application availability. The patch uses the `PerceptibleReciprocal()` to prevent the divide-by-zero from occurring. This flaw affects ImageMagick versions prior to ImageMagick 7.0.8-68.

EPSS 0.16% · 36.3th percentile

Risk Scores

EPSS Score
0.16%
36.3th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSimagemagick0, 8:6.9.10.23+dfsg-2.1ubuntu3, 8:6.9.10.23+dfsg-2.1ubuntu8
Ubuntu:18.04:LTSimagemagick8:6.9.7.4+dfsg-16ubuntu6.4, 8:6.9.7.4+dfsg-16ubuntu6.7, 0
Ubuntu:Pro:16.04:LTSimagemagick8:6.8.9.9-7ubuntu5.12, 8:6.8.9.9-7ubuntu5.13, 8:6.8.9.9-7ubuntu5.14

Timeline

References

Open in Interactive Console →