7.1

CVE-2021-20245

A flaw was found in ImageMagick in coders/webp.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Imagemagick ≫ Imagemagick Version < 6.9.11-62
Imagemagick ≫ Imagemagick Version >= 7.0.0 < 7.0.10-62
Redhat ≫ Enterprise Linux Version 6.0
Redhat ≫ Enterprise Linux Version 7.0
Redhat ≫ Enterprise Linux Version 8.0
Fedoraproject ≫ Fedora Version 33
Debian ≫ Debian Linux Version 9.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.21% 0.643
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
NIST 7.1 8.6 6.9
AV:N/AC:M/Au:N/C:N/I:N/A:C
CWE-369 Divide By Zero

The product divides a value by zero.

https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html
Third Party Advisory
Mailing List
https://lists.debian.org/debian-lts-announce/2023/05/msg00020.html
https://bugzilla.redhat.com/show_bug.cgi?id=1928943
Patch
Third Party Advisory
Issue Tracking
https://github.com/ImageMagick/ImageMagick/issues/3176
Patch
Third Party Advisory
Issue Tracking