Impact
ImageMagick contains a use‑after‑free flaw in the RSVG decoder that occurs when the program is built without Cairo support. A crafted RSVG image that reaches a resource limit triggers the decoder to free the same memory location twice and then access it, causing the ImageMagick process to crash. Because the crash terminates the processing thread, an attacker can execute a denial‑of‑service attack against any system that parses such an image.
Affected Systems
All installations of ImageMagick prior to version 7.1.2-30 and 6.9.13-55 that are compiled without Cairo support are vulnerable. The issue has been fixed in releases 7.1.2-30 and 6.9.13-55 and later upward. Users running older builds on any platform (Linux, Windows, macOS) are affected unless they compile with Cairo enabled or otherwise disable RSVG handling.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity. No EPSS score is available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog. Based on the description, it is inferred that attackers would need access to a system that accepts image uploads or otherwise processes RSVG files, and that the exploit path is local or remote via a web or file‑processing service. No evidence of remote code execution is present, so the attack primarily results in a denial‑of service rather than full system compromise.
OpenCVE Enrichment