Impact
ImageMagick versions prior to 7.1.2-31 and 6.9.13-56 contain a flaw in the FLIF encoder that performs a division by zero when processing an image with an incorrect ticks‑per‑second value. The division by zero causes the encoder to crash, resulting in a denial of service. The weakness is a classic arithmetic error, classified as CWE-369.
Affected Systems
The vulnerability affects all ImageMagick products; any installation of ImageMagick older than version 7.1.2-31 or 6.9.13-56 is impacted. Users of these releases should verify the installed version and plan an upgrade.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is 0.00285, indicating a very low likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog, suggesting no known current exploitation. The likely attack vector is local or remote input of a malicious image to the FLIF encoder, causing the encoder to crash and denying service to the application or system using ImageMagick.
OpenCVE Enrichment