vulnerability
Amazon Linux AMI 2: CVE-2021-20309: Security patch for ImageMagick (ALAS-2024-2559)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
8 | (AV:N/AC:L/Au:N/C:N/I:N/A:C) | 05/11/2021 | 05/31/2024 | 05/31/2024 |
Severity
8
CVSS
(AV:N/AC:L/Au:N/C:N/I:N/A:C)
Published
05/11/2021
Added
05/31/2024
Modified
05/31/2024
Description
A flaw was found in ImageMagick in versions before 7.0.11 and before 6.9.12, where a division by zero in WaveImage() of MagickCore/visual-effects.c may trigger undefined behavior via a crafted image file submitted to an application using ImageMagick. The highest threat from this vulnerability is to system availability.
Solution(s)
amazon-linux-ami-2-upgrade-imagemagickamazon-linux-ami-2-upgrade-imagemagick-camazon-linux-ami-2-upgrade-imagemagick-c-develamazon-linux-ami-2-upgrade-imagemagick-debuginfoamazon-linux-ami-2-upgrade-imagemagick-develamazon-linux-ami-2-upgrade-imagemagick-docamazon-linux-ami-2-upgrade-imagemagick-perl

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.