Impact
ImageMagick is a widely used free image manipulation library. A missing depth check in the MVG decoder causes a stack overflow when a crafted MVG file is parsed, which can corrupt the stack buffer and lead to a crash or service interruption. The weakness is categorized as CWE-400 (Uncontrolled Resource Consumption), CWE-674 (Uncontrolled Recursion), and CWE-787 (Buffer Overflow).
Affected Systems
All installations of ImageMagick older than 6.9.13-51 and 7.1.2-26 are affected, regardless of configuration, because the bug exists in the core decoder. Any instance that processes untrusted MVG files—whether locally or via a network‑exposed interface—falls within risk scope.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector involves delivering a malicious MVG file to the ImageMagick instance—for example by uploading a crafted image to a web application that uses ImageMagick for processing. The CVSS score of 5.3 denotes a moderate risk level for exploitation. An EPSS score of < 1 and absence of a listing in the CISA KEV catalog indicate a low probability of active exploitation at present. The flaw results solely in a denial of service; there is no evidence of remote code execution capabilities.
OpenCVE Enrichment
Debian DLA
Debian DSA