Impact
ImageMagick versions before 7.1.2‑26 and before 6.9.13‑51 allow an attacker to read a single byte beyond the end of a profile buffer when the identify command is run with debug output enabled and the profile value is not printable. The vulnerability is an out‑of‑bounds read (CWE‑125) that can disclose one byte of data.
Affected Systems
The affected product is ImageMagick from the ImageMagick vendor. All releases prior to 7.1.2‑26 and prior to 6.9.13‑51 are vulnerable.
Risk and Exploitability
The CVSS score of 2.1 indicates low overall impact, and the EPSS score of less than 1 % suggests a very low exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the identify command to be executed with debug output enabled. No privilege escalation or remote code execution is achieved by this flaw.
OpenCVE Enrichment
Debian DLA