ZeroHour

CVE-2021-20310

CVSS 3.1
7.5 high
EPSS
1%p68
Published
()
Modified
Description

A flaw was found in ImageMagick in versions before 7.0.11, where a division by zero ConvertXYZToJzazbz() of MagickCore/colorspace.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The highest threat from this vulnerability is to system availability.

Vendors
imagemagick
Products
imagemagick
Weakness
CWE-369
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.