Impact
A heap buffer overflow exists in the MVG decoder of ImageMagick before version 6.9.13‑51 and 7.1.2‑26. When a crafted MVG file is processed, the decoder writes beyond the end of a heap buffer, potentially corrupting adjacent memory. The CVE description notes that this out‑of‑bounds write could lead to memory corruption but does not state that it escalates to remote code execution, denial of service, or other concrete operational impacts.
Affected Systems
All systems that run ImageMagick and process MVG images are affected, including command‑line utilities, shared libraries, and applications embedding ImageMagick. Versions earlier than 6.9.13‑51 and 7.1.2‑26 are vulnerable; later releases are fixed.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and an EPSS score of < 1 % suggests that exploitation is rare. The issue is not listed in the CISA KEV catalog. Based on the description, a maliciously crafted MVG file could cause an out‑of‑bounds write if provided to a vulnerable component; the exact attack vector (local or remote) is not explicitly stated and is therefore inferred.
OpenCVE Enrichment
Debian DLA
Debian DSA