PT-2026-24127 · Unknown · Imagemagick
Ylwango613
·
Published
2026-01-01
·
Updated
2026-04-20
·
CVE-2026-28688
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 7.1.2-16
ImageMagick versions prior to 6.9.13-41
Description
ImageMagick is software used for editing and manipulating digital images. A heap-use-after-free issue exists in the MSL encoder, where an image is destroyed twice. The MSL coder does not support writing MSL, and the write capability has been removed.
Recommendations
Update ImageMagick to version 7.1.2-16 or later.
Update ImageMagick to version 6.9.13-41 or later.
Exploit
Fix
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imagemagick