Impact
ImageMagick has a missing end‑of‑file check while decoding bzip2‑compressed images, which can cause an infinite loop that exhausts CPU and memory. The result is a denial of service affecting any service that processes images with ImageMagick. This weakness corresponds to CWE‑400 (Uncontrolled Resource Consumption) and CWE‑835 (Infinite Loop).
Affected Systems
Vendor ImageMagick with product ImageMagick. All releases older than 7.1.2‑32 and older than 6.9.13‑57 are vulnerable. The problem is fixed in those exact release numbers and later versions.
Risk and Exploitability
The CVSS score of 5.9 classifies the issue as moderate severity. No EPSS data is available, so the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the delivery of a crafted bzip2 image to any application that calls ImageMagick for image manipulation. An attacker who can supply such input can force an indefinite loop, draining system resources and disrupting service availability. No remote code execution or privilege escalation is possible.
OpenCVE Enrichment