Impact
ImageMagick versions earlier than 7.1.2‑15 contain a heap‑buffer‑overflow read flaw in the GetPixelIndex function. The defect occurs when OpenPixelCache updates channel metadata before allocating pixel‑cache memory. An attacker can trigger memory or disk allocation failures that cause a read past the allocated buffer. The vulnerability is classified as CWE‑125, indicating incorrect access of memory buffers, and does not provide arbitrary code execution capability.
Affected Systems
The flaw is present in all releases of ImageMagick older than 7.1.2‑15, affecting the core library that processes any image format handled by the software. Systems running these older builds and using ImageMagick for image manipulation—whether through applications, services, or third‑party integrations—are vulnerable. Any component that writes image data with GetPixelIndex can trigger the issue
Risk and Exploitability
The CVSS score of 2.1 classifies the vulnerability as low severity, and the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. The most likely attack vector is remote, whereby a specially crafted image file is delivered to a vulnerable application that employs ImageMagick. While the risk is considered low, environments that process untrusted image data should still address the vulnerability promptly
OpenCVE Enrichment