CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.5. See the original NVD description below for full technical details.
CVE
CVE-2020-27770
Severity
MEDIUM
CVSS
5.5
EPSS
1.13%
Original NVD Description
Due to a missing check for 0 value of `replace_extent`, it is possible for offset `p` to overflow in SubstituteString(), causing potential impact to application availability. This could be triggered by a crafted input file that is processed by ImageMagick. This flaw affects ImageMagick versions prior to 7.0.8-68.
Related CVEs
Other vulnerabilities affecting the same vendor(s)