Impact
ImageMagick versions before 7.1.2‑26 contain a memory‑leak bug in the VIFF encoder that occurs when the system cannot allocate more memory. In that situation the encoder fails to release the previously allocated buffer, causing the memory usage to grow with each failed allocation. With a maliciously crafted VIFF image an attacker can repeatedly trigger the failure path, slowly draining system memory until the process crashes or becomes unresponsive, leading to denial of service.
Affected Systems
All releases of ImageMagick that provide VIFF image support are affected, including all versions earlier than 7.1.2‑26. Any environment that installs ImageMagick and allows the application to process VIFF images—whether through a web service, desktop conversion tool, or embedded library—remains vulnerable. The impact therefore applies to any platform that has ImageMagick with the default VIFF codec enabled.
Risk and Exploitability
The CVSS base score of 2.1 indicates a low severity that mainly threatens availability. The EPSS score of less than 1% shows a very low likelihood that this vulnerability will be actively exploited by attackers, and it is not listed in the CISA KEV catalogue. The attack vector is likely remote when an external image can be supplied to an exposed ImageMagick service, or local for insider or compromised application usage. Overall the risk is low to moderate; however, an uncontrolled memory sink can still affect uptime of image‑processing services if the vulnerability is triggered.
OpenCVE Enrichment
Debian DLA