Impact
ImageMagick implements a buffer over‑write when processing an X11 import that contains a crafted window title. The vulnerability allows a malformed title string to exceed the bounds of a heap buffer, corrupting adjacent memory. The resulting heap corruption causes the application to crash, providing denial of service to users running the vulnerable version. No evidence is provided that this flaw permits arbitrary code execution or privilege escalation.
Affected Systems
The issue exists in ImageMagick releases prior to 7.1.2-26 and in ImageMagick 6.9.13-51. Users running these or earlier versions of the ImageMagick product are therefore vulnerable.
Risk and Exploitability
The CVSS score is 1.0, indicating a low overall severity, and the EPSS score is below 1 %. The vulnerability is not listed in the CISA KEV catalog. Exploitation would likely require local access to a system capable of running an X11 import with controlled window titles, so the attack vector is inferred to be local or potentially remote if one can inject X11 requests into the target environment. Given the low severity and low likelihood of exploitation, the risk is considered low but patching is recommended to avoid DoS incidents.
OpenCVE Enrichment
Debian DLA