Impact
ImageMagick versions before 7.1.2‑26 and 6.9.13‑51 contain a use‑after‑free flaw that occurs when the freetype library fails to initialize. Instead of aborting, the program continues to use memory that has already been freed, which can cause crashes during image processing and lead to denial of service. The weakness matches CWE‑416 and the broader memory corruption CWE‑825.
Affected Systems
The vulnerability affects ImageMagick installations from the ImageMagick vendor. Any system running a version older than 7.1.2‑26 or older than 6.9.13‑51 is susceptible.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity, while the EPSS score of <1% suggests a very low but non‑zero exploitation probability. The flaw is not listed in the CISA KEV catalog. It can be triggered by supplying a crafted image to an ImageMagick instance that processes user data; the likely attack vector is remote, via an application that accepts arbitrary images, but local exploitation is also possible and does not require special privileges.
OpenCVE Enrichment
Debian DLA