Impact
ImageMagick before 7.1.2-19 contains a memory leak in the PNG encoder when writing MNG images, allowing an attacker to trigger the encoder failure condition, which exhausts memory resources and results in a denial of service. The weakness is a memory management issue, classified as CWE-401. The vulnerability does not confer confidentiality or integrity benefits, but it can disrupt service availability for local or remote consumers of the image processing function until the process crashes or restarts.
Affected Systems
The affected vendor is ImageMagick, product ImageMagick. Versions prior to 7.1.2-19 are vulnerable. No specific sub‑versions are listed; all releases before the release date of 7.1.2-19 may be impacted.
Risk and Exploitability
The CVSS score is 6.3, indicating moderate severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog. Attackers likely need the ability to supply an MNG image to the affected PNG encoder, suggesting a remote or local attack path if an image‑processing service is exposed or if the application processes user‑supplied images. Once the leak is triggered, available memory drains, causing the process to crash or become unresponsive, thereby denying service to legitimate users.
OpenCVE Enrichment
Debian DLA
Debian DSA