Impact
ImageMagick’s PNM parser contains a NULL pointer dereference that is triggered when an allocation fails after a memory limit is reached. If an attacker supplies a malicious or sufficiently large PNM image, the program will crash, resulting in a denial of service. This vulnerability is a classic null pointer dereference flaw (CWE‑476) and does not provide an attacker with arbitrary code execution or data exfiltration capabilities.
Affected Systems
The issue affects all versions of ImageMagick before 7.1.2‑31 and before 6.9.13‑56. These releases are used in various web servers, multimedia processing pipelines, and content management systems that rely on ImageMagick for image manipulation.
Risk and Exploitability
With a CVSS score of 2.3 the severity is low, but the practical impact—application crashes—can disrupt service availability. The EPSS score is less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting limited public exploitation. The likely attack vector is the processing of a malicious PNM file by an underlying application; this is inferred from the description of the crafted input that triggers the failure.
OpenCVE Enrichment