PT-2026-21587 · Unknown+3 · Imagemagick+3
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 7.1.2-15
ImageMagick versions prior to 6.9.13-40
Description
ImageMagick is software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted PCD file lacking a valid Sync marker causes the
DecodeImage() function to enter an infinite loop while searching for the marker. This results in the program becoming unresponsive and consuming CPU resources, potentially leading to system resource exhaustion and a denial of service.Recommendations
Update to ImageMagick version 7.1.2-15 or later.
Update to ImageMagick version 6.9.13-40 or later.
Exploit
Fix
DoS
Out of bounds Read
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Imagemagick
Linuxmint
Red Os
Ubuntu