Impact
A memory leak occurs in the hough lines operation when certain failures happen in ImageMagick prior to version 7.1.2‑26 and in the 6.9.13‑51 release. The leak is small; the description does not specify the cumulative effect on system memory or performance. This weakness is classified as CWE‑401 and CWE‑772 and is reflected in a low CVSS score of 2.1, indicating limited impact when used alone.
Affected Systems
ImageMagick, versions before 7.1.2‑26 and the 6.9.13‑51 release.
Risk and Exploitability
The CVSS score of 2.1 and an EPSS of less than 1% suggest this vulnerability is rarely exploited and of low severity. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation would require an attacker to trigger in the hough lines operation. The vulnerability description does not specify an attack vector, so it is inferred that such a failure might be induced by providing malformed image input. Therefore, the overall risk is modest, with a limited chance of causing resource exhaustion over time.
OpenCVE Enrichment
Debian DLA