logo

Fuzzing ImageMagick and Digging Deeper into CVE-2020-27829

ID: 098fafc7-375d-5931-853c-b5164c577eae

STIX ID: report--098fafc7-375d-5931-853c-b5164c577eae

Feed Name: McAfee Labs Blog

Threat Score
50/100

Date Published: 2021-06-30

Date Updated: 2026-04-28

Author: Hardik Shah

...
...

McAfee describes discovery and root-cause analysis of CVE-2020-27829: an out-of-bounds heap read in ImageMagick's TIFF strip handling that caused crashes when processing crafted TIFF files. The report details fuzzing setup, how insufficient allocation and pointer stride math led to reading past a 248-byte buffer (requiring ~448 bytes), the upstream patch that doubled the allocation, and a subsequent fix to ensure the full allocation is zeroed; a patched ImageMagick 7.0.46 was released.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.