AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2020-25676

MEDIUM · CVSS 5.5 EPSS 1.17%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2020-12-08 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.5. See the original NVD description below for full technical details.

CVE
CVE-2020-25676
Severity
MEDIUM
CVSS
5.5
EPSS
1.17%

Original NVD Description

In CatromWeights(), MeshInterpolate(), InterpolatePixelChannel(), InterpolatePixelChannels(), and InterpolatePixelInfo(), which are all functions in /MagickCore/pixel.c, there were multiple unconstrained pixel offset calculations which were being used with the floor() function. These calculations produced undefined behavior in the form of out-of-range and integer overflows, as identified by UndefinedBehaviorSanitizer. These instances of undefined behavior could be triggered by an attacker who is able to supply a crafted input file to be processed by ImageMagick. These issues could impact application availability or potentially cause other problems related to undefined behavior. This flaw affects ImageMagick versions prior to 7.0.9-0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)