Impact
The MNG decoder in ImageMagick does not fully initialize pixel buffers, with stale data. When a crafted MNG decoder can reveal these uninitialized bytes, exposing previously stored information. The flaw is categorized as CWE‑200 (Information Exposure) and CWE‑908 (Improper Handling of Untrusted Input). Based on the description, it is inferred that an attacker can craft a malicious MNG file to exploit the uninitialized buffer.
Affected Systems
ImageMagick versions older than 6.9.13‑51 and 7.1.2‑26 are vulnerable whenever they process MNG images. This includes web applications, image‑processing services, command‑line tools, or any other component that can load MNG files. The risk applies to any installation of the ImageMagick product that enables MNG decoding.
Risk and Exploitability
With a CVSS score of 5.3, the severity is considered medium. The EPSS score of less than 1% indicates a very low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV. An attacker would need to supply a malicious MNG file through an image ingestion pathway—such as a file upload, API call, or direct file processing—to trigger the decoder and potentially read uninitialized memory that may contain previously stored data. These details are inferred from the description and are not explicitly stated as an attack path in the advisories.
OpenCVE Enrichment
Debian DLA
Debian DSA