CVE Vulnerabilities

CVE-2021-20241

Divide By Zero

Published: Mar 09, 2021 | Modified: May 22, 2023
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
5.5 LOW
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Ubuntu
LOW

A flaw was found in ImageMagick in coders/jp2.c. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of math division by zero. The highest threat from this vulnerability is to system availability.

Weakness

The product divides a value by zero.

Affected Software

Name Vendor Start Version End Version
Imagemagick Imagemagick * 6.9.11-62 (excluding)
Imagemagick Imagemagick 7.0.10 (including) 7.0.10-62 (excluding)
Imagemagick Ubuntu bionic *
Imagemagick Ubuntu devel *
Imagemagick Ubuntu esm-apps/jammy *
Imagemagick Ubuntu esm-infra-legacy/trusty *
Imagemagick Ubuntu esm-infra/xenial *
Imagemagick Ubuntu focal *
Imagemagick Ubuntu groovy *
Imagemagick Ubuntu hirsute *
Imagemagick Ubuntu impish *
Imagemagick Ubuntu jammy *
Imagemagick Ubuntu kinetic *
Imagemagick Ubuntu lunar *
Imagemagick Ubuntu mantic *
Imagemagick Ubuntu noble *
Imagemagick Ubuntu oracular *
Imagemagick Ubuntu trusty *
Imagemagick Ubuntu trusty/esm *
Imagemagick Ubuntu xenial *

References