A call to ConformPixelInfo() in the SetImageAlphaChannel() routine of /MagickCore/channel.c caused a subsequent heap-use-after-free or heap-buffer-overflow READ when GetPixelRed() or GetPixelBlue() was called. This could occur if an attacker is able to submit a malicious image file to be processed by ImageMagick and could lead to denial of service. It likely would not lead to anything further because the memory is used as pixel data and not e.g. a function pointer. This flaw affects ImageMagick versions prior to 7.0.9-0.
                
            Metrics
Affected Vendors & Products
References
        History
                    No history.
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: redhat
Published: 2020-12-08T20:57:39
Updated: 2024-08-04T15:40:36.616Z
Reserved: 2020-09-16T00:00:00
Link: CVE-2020-25663
 Vulnrichment
                        Vulnrichment
                    No data.
 NVD
                        NVD
                    Status : Modified
Published: 2020-12-08T21:15:12.420
Modified: 2024-11-21T05:18:23.650
Link: CVE-2020-25663
 Redhat
                        Redhat
                     ReportizFlow
ReportizFlow