Fuzzing ImageMagick and Digging Deeper into CVE-2020-27829
ID: 098fafc7-375d-5931-853c-b5164c577eae
STIX ID: report--098fafc7-375d-5931-853c-b5164c577eae
Feed Name: McAfee Labs Blog
McAfee describes discovery and root-cause analysis of CVE-2020-27829: an out-of-bounds heap read in ImageMagick's TIFF strip handling that caused crashes when processing crafted TIFF files. The report details fuzzing setup, how insufficient allocation and pointer stride math led to reading past a 248-byte buffer (requiring ~448 bytes), the upstream patch that doubled the allocation, and a subsequent fix to ensure the full allocation is zeroed; a patched ImageMagick 7.0.46 was released.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
