Heap-Based Buffer Over-Read in ImageMagick During TIFF Image Decoding
CVE-2020-13902
7.1HIGH
What is CVE-2020-13902?
A vulnerability in ImageMagick allows for a heap-based buffer over-read during the decoding of TIFF images. This issue arises in the BlobToStringInfo function within the MagickCore/string.c file. Attackers could exploit this flaw to potentially retrieve sensitive information from the memory, posing a risk to data confidentiality for users leveraging affected versions of the software.