Candidate: CVE-2020-27829 PublicDate: 2021-03-26 17:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-27829 Description: A heap based buffer overflow in coders/tiff.c may result in program crash and denial of service in ImageMagick before 7.0.10-45. Ubuntu-Description: Notes: mdeslaur> introduced by: mdeslaur> https://github.com/ImageMagick/ImageMagick6/commit/b874d50070557eb98bdc6a3095ef4769af583dd2 Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H [5.5 MEDIUM] Patches_imagemagick: upstream: https://github.com/ImageMagick/ImageMagick6/commit/e30be60bd97313b80e2701239728a3f47c570817 upstream_imagemagick: released (8:6.9.11.57+dfsg-1) precise/esm_imagemagick: DNE trusty_imagemagick: ignored (out of standard support) trusty/esm_imagemagick: DNE xenial_imagemagick: ignored (end of standard support, was needs-triage) esm-infra/xenial_imagemagick: not-affected (code not present) bionic_imagemagick: not-affected (code not present) focal_imagemagick: not-affected (code not present) groovy_imagemagick: not-affected (code not present) hirsute_imagemagick: not-affected (8:6.9.11.60+dfsg-1ubuntu1) impish_imagemagick: not-affected (8:6.9.11.60+dfsg-1ubuntu1) jammy_imagemagick: not-affected (8:6.9.11.60+dfsg-1ubuntu1) devel_imagemagick: not-affected (8:6.9.11.60+dfsg-1ubuntu1)