Impact
imageMagick versions before 6.9.13-56 and 7.x before 7.1.2-31 process PostScript files without properly escaping certain values that are written to the output. Attackers can craft input files that embed arbitrary PostScript code, which will be executed when the image is processed or re‑converted. This flaw is the instance of CWE-94, a code injection weakness that can lead to untrusted code execution in the context of the ImageMagick process.
Affected Systems
The vulnerability affects ImageMagick’s core product, specifically releases prior to 6.9.13-56 and all 7.x releases before 7.1.2-31. Systems running these versions, regardless of operating system, may be impacted if they handle PostScript input or generate PostScript output with ImageMagick.
Risk and Exploitability
The CVSS score of 6.0 indicates moderate severity, reflecting the potential for code injection but also suggesting that successful exploitation likely requires both the ability to supply crafted input and for the processed file to trigger execution of the injected code. EPSS data is not available, and the vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector involves an attacker supplying a malicious PostScript file to an application that uses ImageMagick to generate or re‑encode images. If the application runs ImageMagick with elevated privileges, the injected code may execute with those privileges.
OpenCVE Enrichment