Impact
A heap buffer overflow exists in the MVG decoder of ImageMagick before version 6.9.13‑51 and 7.1.2‑26. When a deliberately malformed MVG file is decoded, the decoder writes past the end of a heap buffer, corrupting adjacent memory. This corruption can result in application crashes, unintended data modification, or other unintended behavior, but there is no indication of remote code execution or denial–of–service beyond these effects.
Affected Systems
Any system that runs ImageMagick, whether the command‑line utilities, shared libraries, or applications that embed ImageMagick, and that processes MVG images, is vulnerable. The vulnerability applies to versions earlier than 6.9.13‑51 and 7.1.2‑26, including older releases in the major 6.x and 7.x branches.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and an EPSS score of less than 1 % suggests that exploitation is unlikely. The CVE is not listed in the CISA KEV catalog. The likely attack vector is local or remote, but only when an untrusted MVG file is provided to a process that includes ImageMagick. Successful exploitation would cause memory corruption rather than direct code execution or denial of service.
OpenCVE Enrichment
Debian DLA
Debian DSA