Out-of-bounds write in ImageMagick - CVE-2020-25664

 

Out-of-bounds write in ImageMagick - CVE-2020-25664

Published: March 21, 2022


Vulnerability identifier: #VU61503
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-25664
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when processing untrusted input within the WriteOnePNGImage() function of the PNG coder at coders/png.c. A remote attacker can create a specially crafted PNG file, pass it to the affected application, trigger an out-of-bounds write and execute arbitrary code on the target system.


Affected software

ImageMagick
Ubuntu
openEuler
Fedora
vdr-skinelchihd
dvdauthor
dmtx-utils
rss-glx
psiconv
converseen
autotrace
WindowMaker
vdr-scraper2vdr
vdr-skinnopacity
chafa
vdr-tvguide
synfig
synfigstudio
eom
pfstools
kxstitch
R-magick
php-pecl-imagick
rubygem-rmagick
imagemagick-common (Ubuntu package)
libimage-magick-perl (Ubuntu package)
libmagickcore-6.q16-dev (Ubuntu package)
libmagickcore-dev (Ubuntu package)
imagemagick (Ubuntu package)
libimage-magick-q16-perl (Ubuntu package)
libmagickcore-6.q16-2-extra (Ubuntu package)
imagemagick-6.q16 (Ubuntu package)
libmagickcore-6-headers (Ubuntu package)
libmagickwand-6.q16-2 (Ubuntu package)
libmagickcore-6.q16-2 (Ubuntu package)
libmagickwand-6.q16-dev (Ubuntu package)
libmagick++-6.q16-dev (Ubuntu package)
libmagickcore-6-arch-config (Ubuntu package)
perlmagick (Ubuntu package)
libmagick++-6.q16-5v5 (Ubuntu package)
ImageMagick-debuginfo
ImageMagick
ImageMagick-c++
ImageMagick-debugsource
ImageMagick-help
ImageMagick-devel
ImageMagick-c++-devel
ImageMagick-perl
digikam
q
vips

How to mitigate CVE-2020-25664

Install updates from vendor's website.

ImageMagick - addressed in versions 6.9.10-68, 7.0.8-68
vdr-skinelchihd - update to 0.5.0-7.fc34
dvdauthor - update to 0.7.2-16.fc34
dmtx-utils - update to 0.7.6-9.fc34.1
rss-glx - update to 0.9.1.p-50.fc34
psiconv - update to 0.9.8-36.fc34
converseen - update to 0.9.9.2-2.fc34
autotrace - update to 0.31.1-62.fc34
WindowMaker - update to 0.95.9-7.fc34
vdr-scraper2vdr - update to 1.0.11-14.20190128gitd9f6cb4.fc34.1
vdr-skinnopacity - update to 1.1.8-1.fc34.1
chafa - update to 1.2.1-6.fc34
vdr-tvguide - update to 1.3.5-1.fc34.1
synfig - update to 1.4.0-1.fc34.1
synfigstudio - update to 1.4.0-3.fc34
eom - update to 1.26.0-1.fc34.1
pfstools - update to 2.1.0-17.fc34.1
kxstitch - update to 2.1.1-6.fc34
R-magick - update to 2.7.3-2.fc34
php-pecl-imagick - update to 3.5.0-1.fc34.1
rubygem-rmagick - update to 4.2.3-5.fc34
imagemagick-common (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
libimage-magick-perl (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
libmagickcore-6.q16-dev (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
libmagickcore-dev (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
imagemagick (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
libimage-magick-q16-perl (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
libmagickcore-6.q16-2-extra (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
imagemagick-6.q16 (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
libmagickcore-6-headers (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
libmagickwand-6.q16-2 (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
libmagickcore-6.q16-2 (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
libmagickwand-6.q16-dev (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
libmagick++-6.q16-dev (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
libmagickcore-6-arch-config (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
perlmagick (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
libmagick++-6.q16-5v5 (Ubuntu package) - update to 8:6.8.9.97ubuntu5.16+esm2
ImageMagick-debuginfo - update to 6.9.10.67-10
ImageMagick - update to 6.9.10.67-10
ImageMagick-c++ - update to 6.9.10.67-10
ImageMagick-debugsource - update to 6.9.10.67-10
ImageMagick-help - update to 6.9.10.67-10
ImageMagick-devel - update to 6.9.10.67-10
ImageMagick-c++-devel - update to 6.9.10.67-10
ImageMagick-perl - update to 6.9.10.67-10
ImageMagick - update to 6.9.12.31-1.fc34
digikam - update to 7.3.0-4.fc34
q - update to 7.11-44.fc34
vips - update to 8.11.3-1.fc34.1

External References

Related Security Bulletins