Impact
ImageMagick before 6.9.13‑56 and 7.x before 7.1.2‑31 is vulnerable to an invalid memory free in the MVG decoder. A crafted MVG image can trigger the bug, causing the application to crash. The resulting impact is a denial of service as legitimate image processing is disrupted, and the vulnerability is a CWE‑763 flaw—incorrect memory deallocation leading to a crash.
Affected Systems
The affected products are ImageMagick ImageMagick, all versions before 6.9.13‑56 and 7.x before 7.1.2‑31. These versions are widely used in web servers, content management systems, and image processing pipelines. If any component relies on MVG decoding, the vulnerability applies. Users running older ImageMagick installations should check their exact version for compliance. No specific vendor patch is listed, but references indicate the vulnerability is remediated in 7.1.2‑31 and later, and earlier 6.9.13‑56 updates.
Risk and Exploitability
The CVSS score of 8.2 marks this issue as high severity. The EPSS score is not available, so the exploitation likelihood is not quantified, and the vulnerability is not in the CISA KEV catalog. Attackers would need to supply a malicious MVG file to the ImageMagick engine, which is typically performed via user‑controlled input such as uploads or processing of external content. This can crash the service or application, leading to service disruption. The vulnerability does not grant arbitrary code execution or data exfiltration, but it can disrupt operations for customers that rely on ImageMagick for image rendering.
OpenCVE Enrichment