ArchLinux: 202006-14: imagemagick: information disclosure
Summary
An out-of-bounds read has been found in the TIFF image decoding part of imagemagick <= 7.0.10-17, in BlobToStringInfo in MagickCore/string.c.
Resolution
Upgrade to 7.0.10.20-1.
# pacman -Syu "imagemagick>=7.0.10.20-1"
The problem has been fixed upstream in version 7.0.10.20.
References
https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=20920 https://github.com/ImageMagick/ImageMagick/discussions/2132 https://github.com/ImageMagick/ImageMagick/commit/824f344ceb823e156ad6e85314d79c087933c2a0 https://security.archlinux.org/CVE-2020-13902
Workaround
None.