Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-56366

Опубликовано: 10 июл. 2026
Источник: debian

Описание

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.18+dfsg1-1package
imagemagickfixed8:7.1.1.43+dfsg1-1+deb13u12trixiepackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9r56-3gjq-hqf7

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/bee248ee853a686a969fae9cfb1e02dd5aae245b (7.1.2-18)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/1adc49fac3041620abe11fcb06524d33d9dbd035 (6.9.13-43)

Связанные уязвимости

CVSS3: 3.3
ubuntu
2 месяца назад

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.

CVSS3: 3.3
redhat
2 месяца назад

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.

CVSS3: 3.3
nvd
2 месяца назад

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.

CVSS3: 4
redos
2 месяца назад

Уязвимость ImageMagick

CVSS3: 4
redos
2 месяца назад

Уязвимость ImageMagick7