Impact
ImageMagick up to version 7.1.2-18 contains a memory leak in the ASHLAR coder that occurs when the coder fails during image processing. The leak prevents the released memory from being reclaimed, allowing an attacker to repeatedly trigger failures and gradually deplete system memory, ultimately causing a denial of service for the affected application or system. The flaw is recorded against CWE‑401 (Memory Leak) and CWE‑770 (Resource Exhaustion).
Affected Systems
All builds of ImageMagick distributed by the ImageMagick project are affected, specifically releases through 7.1.2-18. Deployments that incorporate these versions without applying a later patch remain vulnerable, whether the library is used in command‑line tools, web services, or embedded applications.
Risk and Exploitability
The vulnerability has a CVSS score of 4.8, indicating moderate severity, and an EPSS score of less than 1 %, implying a very low exploitation probability in the wild. It is not listed in CISA’s KEV catalog. The likely attack vector is local or remote, depending on whether the ImageMagick processor is exposed via a service or accepts untrusted images; an attacker would need to supply crafted image data that provokes the ASHLAR coder to fail. The effect of such exploitation is resource exhaustion leading to denial of service.
OpenCVE Enrichment