VYPR
Medium severity5.5NVD Advisory· Published Dec 8, 2020· Updated Jun 17, 2026

CVE-2020-25667

CVE-2020-25667

Description

TIFFGetProfiles() in /coders/tiff.c calls strstr() which causes a large out-of-bounds read when it searches for "dc:format=\"image/dng\" within profile due to improper string handling, when a crafted input file is provided to ImageMagick. The patch uses a StringInfo type instead of a raw C string to remedy this. This could cause an impact to availability of the application. This flaw affects ImageMagick versions prior to 7.0.9-0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*range: <6.9.10-69
    • (no CPE)range: <7.0.9-0
  • ImageMagick/ImageMagickdescription

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.