Impact
ImageMagick before version 7.1.2-30 and the 6.9.13-55 releases contain an uncontrolled recursion flaw in the CALS decoder. The lack of a depth check allows an attacker to craft a CALS image that causes the decoder to recurse without bound, eventually depleting the process stack and crashing the image processing service. This failure to complete normally results in a denial of service for the affected application or service that relies on ImageMagick to handle image files.
Affected Systems
The vulnerability affects ImageMagick for all platforms where the 7.x series prior to 7.1.2-30 or the 6.9.x series prior to 6.9.13-55 is installed. These include both the stable 7.x release tree and the older 6.9.x releases, with no specific hotfixes mentioned in the advisory.
Risk and Exploitability
The CVSS base score of 6.9 indicates moderate severity, and the EPSS score is currently unavailable, meaning no quantified likelihood is provided. The vulnerability is not listed in the CISA KEV catalog. Because the flaw is triggered by a crafted CALS image, the likely attack vector is remote or local where an application accepts untrusted image data; the attacker does not need elevated privileges, making the vulnerability exploitable in many deployment scenarios. Successful exploitation leads only to service disruption, but many systems rely on image rendering for user interaction, making the impact significant in a production environment.
OpenCVE Enrichment