CVE-2021-20243 Information
Jun 07, 2022
cve
Description
A flaw was found in ImageMagick in MagickCore/resize.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Reference
https://github.com/ImageMagick/ImageMagick/pull/3193 https://bugzilla.redhat.com/show_bug.cgi?id=1928958 https://lists.debian.org/debian-lts-announce/2021/06/msg00000.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
UNCHANGED
Integrity Impact
NONE
Availability Impact
NONE
Base Score
HIGH
Base Severity
5.5
Share on: