Impact
ImageMagick is an image manipulation library. A failure to allocate memory during CheckPrimitiveExtent results in a heap‑use‑after‑free. The flaw can cause the program to crash but does not provide direct control over code execution. The weakness is classified as CWE‑416. Exploitation would lead to a denial‑of‑service condition, disrupting services that rely on ImageMagick for image processing.
Affected Systems
Versions prior to 6.9.13‑50 and 7.1.2‑25 of ImageMagick are affected. The vulnerability applies to the ImageMagick application across all supported platforms where older binaries are used.
Risk and Exploitability
The CVSS score is 5.9, indicating a moderate risk assessment. EPSS is not available, so the likelihood of exploitation cannot be quantified. The flaw is not listed in CISA’s KEV catalog. The attack would likely occur when an attacker supplies a specially crafted image file to a service that invokes the vulnerable allocation path, potentially causing the application to crash.
OpenCVE Enrichment