Security Advisory

CVE-2021-20310

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2021-05-11 22:30:40
Last updated 2024-08-03 17:37:23
Assigner redhat
State PUBLISHED

Description

A flaw was found in ImageMagick in versions before 7.0.11, where a division by zero ConvertXYZToJzazbz() of MagickCore/colorspace.c may trigger undefined behavior via a crafted image file that is submitted by an attacker and processed by an application using ImageMagick. The highest threat from this vulnerability is to system availability.