Impact
ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 include a heap-use-after-free flaw in the GetList method of PerlMagick. A crafted invocation of GetList can trigger an out-of-bounds access, causing the process to crash. The result of the exploitation is a denial of service as the affected ImageMagick instance (or any application calling it) becomes unavailable until it is restarted.
Affected Systems
All installations of ImageMagick older than version 7.1.2-30, as well as 6.9.x releases prior to 6.9.13-55, run the vulnerable PerlMagick component. The impact applies to any environment where ImageMagick is invoked, whether as a standalone tool or integrated into another application.
Risk and Exploitability
The vulnerability has a CVSS score of 4.8, indicating moderate severity. The EPSS score is not available and it is not listed in the CISA KEV catalog, suggesting a lower priority for widespread exploitation at present. The flaw requires a crafted call to GetList and may be exercised via remote or local input depending on how the application uses PerlMagick. Because the outcome is a crash rather than arbitrary code execution, the primary risk is that services relying on ImageMagick become unavailable.
OpenCVE Enrichment