Impact
ImageMagick before 7.1.2-26 and 6.9.13-51 lacks a check for the allowed memory allocation limit when performing matrix-backed operations such as -canny. An attacker can supply a crafted image that causes the library to allocate more memory than the configured policy permits, which can exhaust system resources and lead to a denial of service. This weakness corresponds to CWE-770, indicating a failure in proper resource management.
Affected Systems
The affected product is ImageMagick, specifically versions prior to 7.1.2-26 and 6.9.13-51. Any system or application that relies on these versions to process images is potentially impacted.
Risk and Exploitability
The CVSS score of 4.8 indicates a moderate impact. likelihood of exploitation, and the vulnerability is not listed in CISA KEV, further reducing the chances of widespread attacks. Attack vector is inferred to involve an attacker supplying a malicious image to. Successful exploitation would consume memory resources and may crash or halt the service handling the image, leading to denial of service. The practical feasibility depends on whether the application memory‑allocation path in the version in use. The EPSS score of < 1% indicates a very low probability of exploitation.
OpenCVE Enrichment
Debian DLA