Impact
ImageMagick before version 7.1.2-22 contains a division by zero flaw in the binomial kernel processing routine. The bug can be triggered by supplying an excessively large binomial kernel value, which causes the internal arithmetic to overflow and the subsequent division by zero, crashing the application. The vulnerability is classified as CWE-190 (Integer Division or Modulo by Zero) and results only in a loss of availability, as an attacker can terminate the ImageMagick process but cannot gain code execution or read sensitive data.
Affected Systems
The vulnerability affects ImageMagick installations running any version prior to 7.1.2-22, including the default builds used by many web servers, content management systems, and batch image processing pipelines. Administrators should review whether their systems incorporate ImageMagick 7.x and verify the installed version number.
Risk and Exploitability
The CVSS score of 4.8 indicates moderate severity, with the EPSS score unavailable but not listed in the CISA KEV catalog. The likely attack vector is local or remote image processing, where an attacker supplies a crafted image containing a large binomial kernel. An attacker does not need administrative privileges but must be able to feed images to the vulnerable ImageMagick instance, which can be a web application or other consumer of image files.
OpenCVE Enrichment
Debian DLA
Debian DSA