Impact
ImageMagick before version 7.1.2‑19 contains an off‑by‑one error in morphology validation that allows out‑of‑bounds heap buffer reads. An attacker can supply malformed morphology parameters, creating a single‑pixel memory access violation that enables reading memory beyond the intended bounds. This flaw can be leveraged to expose sensitive information that the ImageMagick process can access. While the description refers to a "heap buffer overflow", the nature of the vulnerability is an over‑read rather than an overwrite. Consequently, the risk is primarily data exposure rather than immediate code execution.
Affected Systems
The affected product is ImageMagick; the issue exists in all releases prior to 7.1.2‑19. No specific platform or operating system filtering is mentioned, so any system running a vulnerable version of ImageMagick is potentially impacted.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity, and the EPSS score is not available, making it difficult to quantify current exploitation likelihood. ImageMagick is not listed in CISA’s KEV catalog. Inference suggests the attack vector requires an attacker to supply a crafted image containing invalid morphology parameters, which could be delivered via local file inclusion, an image upload feature, or a remote image processing endpoint. The presence of the off‑by‑one error provides an exploitation opportunity, but no direct evidence of active exploitation is reported.
OpenCVE Enrichment
Debian DLA
Debian DSA