Impact
ImageMagick's PSD format handler contains a heap information disclosure flaw. When a PSD file includes ZIP‑compressed layer data that decompresses to less than the expected size, uninitialized heap memory is leaked into the output image. This leak can expose confidential data that resided in the process’s memory at the time of processing, leading to inadvertent disclosure of sensitive information.
Affected Systems
All releases of ImageMagick older than version 7.1.2‑15 and older than version 6.9.13‑40 are affected. The vulnerability is limited to the handling of Adobe Photoshop PSD files and does not extend to other image formats.
Risk and Exploitability
The flaw is rated CVSS 7.5, indicating moderate to high risk. EPSS shows a probability of exploitation below 1%, suggesting a low likelihood of abuse. The vulnerability is not listed in the CISA KEV catalog. The description does not specify an attack vector, but it is reasonable to infer that an attacker could supply a malicious PSD file—through uploads, attachments, or other import mechanisms—to trigger the memory leak and obtain sensitive data.
OpenCVE Enrichment
Debian DLA
Debian DSA
Github GHSA