Impact
ImageMagick libraries vulnerable to a heap buffer overflow in the FTXT encoder due to missing boundary checks when parsing the ftxt:format parameter. A remote attacker can supply a crafted FTXT image file that triggers an out‑of‑bounds read, permitting either a denial of service or a partial information disclosure by exposing data located beyond the intended buffer. This flaw restricts the confidentiality and availability of a system that processes untrusted FTXT images and can be exercised over the network.
Affected Systems
All installations of ImageMagick earlier than version 7.1.2‑19 are affected, including the open source ImageMagick distribution identified by the vendor ImageMagick and product ImageMagick. The vulnerability exists regardless of the host operating system and applies to all builds that support the FTXT format encoder.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate severity, and the EPSS score is < 1%, indicating a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attackers can exploit the vulnerability remotely by sending malicious FTXT files to an application that processes images through ImageMagick, making the risk primarily a denial‑of‑service or information disclosure threat to systems that accept untrusted images.
OpenCVE Enrichment