Impact
ImageMagick before version 7.1.2-31 is vulnerable to a heap buffer overflow in its distributed pixel cache server. When a client sends specially crafted data, the server overwrites heap memory and crashes, resulting in a denial of service. The flaw is a classic heap corruption that does not grant code execution but can bring the service down.
Affected Systems
All installations of ImageMagick running the distributed pixel cache server prior to release 7.1.2-31 are affected. This includes common deployments that expose the pixel cache server over the network without additional access controls.
Risk and Exploitability
The CVSS score of 6 indicates a moderate risk. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers need network access to the distributed pixel cache server and can trigger the crash by sending crafted data, leading to a local denial of service if the affected component is critical to operations.
OpenCVE Enrichment