Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-33901

Опубликовано: 13 апр. 2026
Источник: debian
EPSS Низкий

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.19+dfsg1-1package

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x9h5-r9v2-vcww

  • https://github.com/ImageMagick/ImageMagick/commit/4c72003e9e54a4ebaa938d239e75f5d285527ebe (7.1.2-19)

  • https://github.com/ImageMagick/ImageMagick6/commit/53db9565c648e71733a5c2cc2a4e8e8a4347d9cd (6.9.13-44)

  • Regression see https://github.com/ImageMagick/ImageMagick6/issues/420

  • Regression fix [1/2]: https://github.com/ImageMagick/ImageMagick/commit/50507967ae868d7d159057bb08897091bc4800a8 (7.1.2-22)

  • Regression fix [2/2]: https://github.com/ImageMagick/ImageMagick/commit/ab89688f34618fba733275ff718a6088c463ba4c (7.1.2-22)

  • Regression fix [1/2]: https://github.com/ImageMagick/ImageMagick6/commit/a86cd0fbc863b1ddb24ffa9168f68baebf02baa4 (6.9.13-47)

  • Regression fix [2/2]: https://github.com/ImageMagick/ImageMagick6/commit/8173c210fc1ea0221150be44459878acd56391cc (6.9.13-47)

EPSS

Процентиль: 44%
0.00566
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
4 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.

CVSS3: 7.5
redhat
4 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.

CVSS3: 7.5
nvd
4 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, a heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.

CVSS3: 7.5
github
4 месяца назад

ImageMagick has a heap Buffer Overflow in ImageMagick MVG decoder

CVSS3: 7.5
fstec
4 месяца назад

Уязвимость декодера формата MVG консольного графического редактора ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 44%
0.00566
Низкий