Impact
ImageMagick before version 7.1.2-31 can leak open file pointers when processing a specially crafted magick script, creating a resource leak that can deplete system file descriptors. This vulnerability is a classic case of CWE‑775, where an unclosed resource can be exploited to exhaust available file descriptors, ultimately disabling the application or causing a denial of service. The impact is limited to the host running ImageMagick, but any service that accepts user–supplied magick scripts could be indirectly affected.
Affected Systems
The vulnerability affects the ImageMagick software suite across all platforms where it is installed. Versions earlier than 7.1.2‑31 are susceptible. The affected product is listed as "ImageMagick:ImageMagick" in vendor terminology. No other proprietary products are listed.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high severity. The EPSS score is not available, so the current exploitation probability is unknown, and the vulnerability is not cited in the CISA KEV catalog. The attack vector is inferred to be local or remote file script injection; to exploit the flaw an attacker must be able to supply a crafted magick script to the ImageMagick process. If the service runs with elevated privileges or processes untrusted scripts, the resource depletion can lead to service interruption.
OpenCVE Enrichment