ImageMagick
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*
- < 7.1.2-15
- < 6.9.13-40
A denial-of-service vulnerability has been identified in ImageMagick versions prior to 7.1.2-15 and 6.9.13-40. The issue arises in the internal SVG decoder, where a crafted SVG file containing a malicious element can cause ImageMagick to attempt to allocate approximately 674 GB of memory. This excessive memory allocation leads to an out-of-memory error, causing the application to abort. The vulnerability was discovered through fuzz testing with AFL++.
Exploitation of this vulnerability causes the application to run out of memory and abort, disrupting any ongoing processes that involve image processing or manipulation.
Users can upgrade to ImageMagick versions 7.1.2-15 or 6.9.13-40 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.