Impact
ImageMagick versions earlier than 6.9.13-56 and all 7.x releases before 7.1.2-31 contain a flaw in the MVG decoder that omits a critical limit check. When a maliciously crafted MVG image is processed, the decoder enters a computation path that can run for an extended period, consuming a large amount of CPU resources and preventing the decoding operation from completing. This leads to a denial of service for any application or service that relies on ImageMagick to render or convert images.
Affected Systems
All deployments of the ImageMagick suite using a version older than 6.9.13-56 or any 7.x release earlier than 7.1.2-31 are potentially affected. The only vendor listed is ImageMagick, and the issue applies across all platforms that run these release lines.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity denial of service. The EPSS score is not available, meaning public data does not provide a probability of exploitation, while the absence from the KEV catalog does not eliminate the threat. The likely attack vector is via any process that accepts externally supplied image files—web servers, content management systems, or other services that invoke ImageMagick. Based on the description, it is inferred that an attacker can supply a malicious MVG image to such a process, triggering the runaway decoding and overwhelming the host’s CPU, which results in service interruption for legitimate users.
OpenCVE Enrichment