Impact
ImageMagick before 7.1.2-31 and before 6.9.13-56 contains a policy bypass in the PCD decoder. When a specific command line option is supplied, the decoder skips an enforced resource limit, leading to excessive memory allocation and a limited availability impact.
Affected Systems
ImageMagick versions before 7.1.2-31 and 6.9.13-56 are affected. The vulnerability impacts the ImageMagick:ImageMagick product as identified by the CNA.
Risk and Exploitability
The CVSS score of 4.8 signals moderate severity. The EPSS score of < 1% indicates a very low exploitation probability, and the vulnerability is not listed in CISA KEV. Exploitation requires local access to ImageMagick's command line; therefore the likelihood of widespread attacks is low, but organizations allowing local command execution should patch promptly to prevent potential denial of service.
OpenCVE Enrichment