ImageMagick
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*
- < 7.1.2-15
- < 6.9.13-40
A memory leak vulnerability has been identified in ImageMagick versions prior to 7.1.2-15 and 6.9.13-40. The issue arises in the MSL component, where the stack index is not properly updated, leading to images being stored incorrectly and not freed in case of an error. This flaw causes memory leaks, as demonstrated by LeakSanitizer, which reported a direct leak of over 13,000 bytes.
Exploitation of this vulnerability leads to memory leaks, where allocated memory is not properly released, potentially causing increased memory usage and degradation of application performance over time.
Users can upgrade to ImageMagick versions 7.1.2-15 or 6.9.13-40 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.