Impact
ImageMagick before 7.1.2‑30 and 6.9.13‑55 does not properly lower the memory budget when an operation inside OpenPixelCache fails, allowing repeated failures to deplete the process memory and cause a denial of service. The flaw is a classic memory allocation issue identified as CWE‑400. The impact is that an attacker can disrupt image‑processing services, leading to unavailable functionality for legitimate users.
Affected Systems
ImageMagick, product ImageMagick, versions prior to 7.1.2‑30 and prior to 6.9.13‑55 are affected. Exact release information beyond those major versions is not provided.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV, suggesting limited evidence of exploitation. The likely attack vector is executing malformed or malicious images that trigger repeated cache failures. Without network‑level remote exploitation paths documented, the risk is somewhat constrained to environments that process untrusted images.
OpenCVE Enrichment