Impact
ImageMagick versions before 6.9.13-55 and before 7.1.2-30 have a use‑after‑free flaw in the RSVG decoder when built without cairo support. When a decoding limit is reached, the decoder accesses freed memory, which can lead to a crash and potentially allow an attacker to cause memory corruption. The weakness is identified as CWE-416.
Affected Systems
The vulnerability affects ImageMagick software distributed under the ImageMagick:ImageMagick vendor/product name. All builds of ImageMagick prior to version 7.1.2-30 (and 6.9.13-55) that are compiled without cairo support are impacted. No specific patch version list is provided beyond the general upgrade to 7.1.2-30 or later.
Risk and Exploitability
The CVSS score of 8.2 indicates high severity, but the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be local, as the flaw is triggered by supplying crafted SVG files during decoding. While the description only mentions a crash, use‑after‑free can potentially lead to more severe memory corruption or execution. The exploitability therefore depends on the attacker’s ability to force the application to process malicious SVG content, which is likely in untrusted input scenarios.
OpenCVE Enrichment