Impact
The vulnerability is a policy bypass in the MAT decoder of ImageMagick that allows a crafted highly compressed MAT image to cause the decoder to create temporary files larger than the configured policy limit. The flaw, identified as CWE-409, enables an attacker to circumvent resource limits and exhaust available disk space, leading to a denial of service by starving system resources and interrupting image processing services.
Affected Systems
All installations of ImageMagick running versions older than 7.1.2-30 or 6.9.13-55 are affected. The issue originates in both the 7.1.x series and the 6.9.x branch, meaning that almost any deployment of the library that has not applied the 7.1.2-30 or 6.9.13-55 release is vulnerable. The impact applies wherever ImageMagick processes MAT images from potentially untrusted users, such as web services, CMS platforms, or batch image conversion tools.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. No EPSS score is available, so the short‑term exploitation likelihood cannot be quantified, and the vulnerability is not yet listed in the CISA KEV catalog. The attack path is inferred to involve the submission of a malicious MAT file to an environment that uses ImageMagick to decode images, after which the decoder writes oversized temporary files to disk. Because the restriction is bypassed, the application can grow its disk usage beyond intended limits, potentially leading to failure of subsequent image processing or other operations.
OpenCVE Enrichment