CVE-2020-13902 log

Source
Severity Medium
Remote Yes
Type Information disclosure
Description
An out-of-bounds read has been found in the TIFF image decoding part of imagemagick <= 7.0.10-17, in BlobToStringInfo in MagickCore/string.c.
Group Package Affected Fixed Severity Status Ticket
AVG-1181 imagemagick 7.0.10.18-1 7.0.10.20-1 Medium Fixed
Date Advisory Group Package Severity Type
28 Jun 2020 ASA-202006-14 AVG-1181 imagemagick Medium information disclosure
References
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=20920
https://github.com/ImageMagick/ImageMagick/discussions/2132
https://github.com/ImageMagick/ImageMagick/commit/824f344ceb823e156ad6e85314d79c087933c2a0
Notes
Fixed in 7.0.10-20.