Buffer Overflow Vulnerability in ImageMagick Software by ImageMagick
CVE-2020-19667
7.8HIGH
Summary
This vulnerability involves a stack-based buffer overflow due to an unconditional jump in the ReadXPMImage function located in coders/xpm.c of ImageMagick. An attacker could potentially exploit this flaw to execute arbitrary code by crafting a malicious image file, leading to a breach of system integrity. Users of ImageMagick 7.0.10-7 are particularly at risk and are advised to apply security patches promptly to safeguard against potential exploitation.
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved