Impact
A heap-use-after-free flaw exists in ImageMagick’s MSL encoder that frees a cloned image twice. The vulnerability is associated with CWE‑416 and may cause memory corruption when the MSL image is processed. The advisory does not explicitly state a crash or arbitrary code execution, only that undefined behavior can result.
Affected Systems
The flaw affects ImageMagick versions earlier than 7.1.2‑16 and 6.9.13‑41. Users of the ImageMagick software stack who rely on the MSL encoder are at risk.
Risk and Exploitability
The CVSS score of 4 indicates a moderate severity. The EPSS score is below 1% and the vulnerability is not listed in KEV, suggesting a low likelihood of widespread exploitation. An attacker would need to supply a crafted MSL image to trigger the issue, potentially during image processing by any software that uses the MSL encoder.
OpenCVE Enrichment
Debian DLA
Debian DSA
Github GHSA