CVE-2020-25665: Debian Linux

Medium severity, CVSS 5.5. EPSS: 1% chance of exploitation in the next 30 days.

The PALM image coder at coders/palm.c makes an improper call to AcquireQuantumMemory() in routine WritePALMImage() because it needs to be offset by 256. This can cause a out-of-bounds read later on in the routine. The patch adds 256 to bytes_per_row in the call to AcquireQuantumMemory(). This could cause impact to reliability. This flaw affects ImageMagick versions prior to 7.0.8-68.

Affected products

  • Debian Debian Linux: version 9.0 only
  • ImageMagick ImageMagick: before 6.9.10-68 (fixed in 6.9.10-68); from 7.0.0-0, before 7.0.8-68 (fixed in 7.0.8-68)

Published 2020-12-08. Last modified 2026-06-17.