Impact
ImageMagick versions before 7.1.2‑31 are vulnerable to a denial‑of‑service attack due to improper handling of XMP profiles. An attacker can embed a malicious XMP profile that causes the parser to miscalculate a numerator and denominator, leading to a crash or hang during image processing. This flaw can result in application downtime or blocked image rendering for users.
Affected Systems
ImageMagick, all releases older than 7.1.2‑31. The vulnerability applies to every instance that parses XMP metadata in images, including command‑line utilities and server‑side image processing pipelines.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. EPSS is not available and the issue is not listed in CISA KEV, suggesting limited public exploitation data. The vulnerability can be triggered by any process that ingests a crafted image, so attackers who can provide malicious files to ImageMagick—whether locally or via a remote application—may force the program to crash or hang. Exploitation requires that ImageMagick parses untrusted XMP data; if an application disables XMP support or runs with limited privileges, the risk is mitigated. Nevertheless, because the failure leads to a denial of service, the potential impact on availability remains significant.
OpenCVE Enrichment