Impact
The vulnerability arises from a 32‑bit integer overflow in the MAT decoder’s arithmetic expression, leading to a heap buffer over‑read. This bug permits an attacker to read data beyond the allocated memory bounds when a carefully crafted MAT image is processed, potentially exposing internal memory contents. The flaw does not provide code execution or privilege escalation, but it can leak sensitive information that could aid in further attacks.
Affected Systems
All installations of ImageMagick older than 7.1.2‑16 and 6.9.13‑41 are affected. The issue exists in the bundled MAT decoder component of these versions. Updated releases 7.1.2‑16 and 6.9.13‑41 contain the patch.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, while the EPSS rate of less than 1 % reflects a very low exploitation probability at time of analysis. ImageMagick is not listed in the CISA Known Exploited Vulnerabilities catalog, further suggesting limited reported exploitation. The flaw requires an attacker to supply a malicious MAT file; no local–remote attack vector is specified, and the impact is confined to information disclosure rather than system compromise. Overall, the risk is modest but patching remains advised.
OpenCVE Enrichment
Debian DLA
Debian DSA
Github GHSA