Impact
ImageMagick’s XCF decoder contains an integer conversion overflow that results in a heap buffer over‑read when a crafted file is processed. The out‑of‑bounds read can corrupt memory and cause the consuming process to crash, interrupting any service that loads the malicious image. The weakness involves integer overflow (CWE‑190), erroneous integer conversion (CWE‑681), and unauthorized buffer access (CWE‑125).
Affected Systems
ImageMagick image‑processing software, versions older than 6.9.13‑51 and 7.1.2‑26, is affected. Any application, service, or embedded library that uses ImageMagick to read XCF files may be impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of <1% suggests that exploitation is currently unlikely. The vulnerability is not listed in CISA KEV, meaning no known public exploits exist yet. Based on the description, it is inferred that the most likely attack vector is the delivery of a maliciously crafted XCF image to any ImageMagick‑based system that processes untrusted input, causing a crash and rendering the affected process unavailable.
OpenCVE Enrichment
Debian DLA
Debian DSA