CVE-2021-20224
Summary
| CVE | CVE-2021-20224 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-08-25 20:15:00 UTC |
| Updated | 2023-03-11 23:15:00 UTC |
| Description | An integer overflow issue was discovered in ImageMagick's ExportIndexQuantum() function in MagickCore/quantum-export.c. Function calls to GetPixelIndex() could result in values outside the range of representable for the 'unsigned char'. When ImageMagick processes a crafted pdf file, this could lead to an undefined behaviour or a crash. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| outside the range of representable values of type 'unsigned char' (#3… · ImageMagick/ImageMagick@5af1dff · GitHub |
MISC |
github.com |
|
| outside the range of representable values of type 'unsigned char' by hifoolno · Pull Request #3083 · ImageMagick/ImageMagick · GitHub |
MISC |
github.com |
|
| [SECURITY] [DLA 3357-1] imagemagick security update |
MLIST |
lists.debian.org |
|
| https://github.com/ImageMagick/ImageMagick/pull/3083 · ImageMagick/ImageMagick6@553054c · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 180975 Debian Security Update for imagemagick (CVE-2021-20224)
- 181625 Debian Security Update for imagemagick (DLA 3357-1)
- 199045 Ubuntu Security Notification for ImageMagick Vulnerabilities (USN-5736-1)
- 199524 Ubuntu Security Notification for ImageMagick Vulnerabilities (USN-6200-1)
- 354798 Amazon Linux Security Advisory for ImageMagick : ALAS2-2023-1971
- 354809 Amazon Linux Security Advisory for ImageMagick : ALAS-2023-1696
- 502534 Alpine Linux Security Update for imagemagick
- 672609 EulerOS Security Update for imagemagick (EulerOS-SA-2023-1318)
- 673058 EulerOS Security Update for imagemagick (EulerOS-SA-2023-2149)
- 752561 SUSE Enterprise Linux Security Update for ImageMagick (SUSE-SU-2022:3138-1)
- 753205 SUSE Enterprise Linux Security Update for ImageMagick (SUSE-SU-2022:3119-1)