Impact
ImageMagick prior to 7.1.2‑31 and 6.9.13‑56 contains a use‑after‑free flaw in the ImagesToBlob method, caused by a pointer that is not updated correctly. The flaw can trigger memory corruption that leads to a limited availability impact, namely a crash of the process that invokes the function. The vulnerability is classified as CWE‑416 and CWE‑825.
Affected Systems
Affected systems are deployments of ImageMagick releases earlier than 7.1.2‑31 and 6.9.13‑56. All environments running these older versions are susceptible; the fix is included in 7.1.2‑31 and 6.9.13‑56 and later.
Risk and Exploitability
The publicly quoted CVSS score is 2.1, indicating low severity, and the EPSS score is < 1%. The vulnerability is not in the CISA KEV catalog. The likely attack vector is an application or system that processes external images; based on the description, it is inferred that an attacker must supply a crafted image that passes through the ImagesToBlob function to trigger the crash. No public exploit is known. Exploitation would cause a denial‑of‑service rather than remote code execution.
OpenCVE Enrichment