Impact
ImageMagick contains a heap out‑of‑bounds read in the DCM decoder that occurs when processing certain DICOM files. The decoder loop mis‑calculates the number of bytes per iteration, causing the function to read beyond the allocated buffer. This flaw can lead either to a crash, denying legitimate use, or to leaking heap data into the output image, exposing sensitive information.
Affected Systems
The affected products are ImageMagick. Versions earlier than 7.1.2‑15 and 6.9.13‑40 are vulnerable; the patch that fixes the defect is included in those releases and later versions.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate impact. The EPSS score of less than 1% signals a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is the processing of a specially crafted DICOM file; this can be local if a user invokes ImageMagick, or remote if the software is used as a service that accepts user input.
OpenCVE Enrichment
Debian DLA
Debian DSA
Github GHSA