Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-56373

Опубликовано: 10 июл. 2026
Источник: debian
EPSS Низкий

Описание

ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.15+dfsg1-1package
imagemagickno-dsatrixiepackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3j4x-rwrx-xxj9

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/168ffe18def968f886c023146a478897866fd621 (7.1.2-14)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/06a0867c1f5076b85577b6b1cf87af901f6d6a84 (6.9.13-39)

EPSS

Процентиль: 14%
0.0023
Низкий

Связанные уязвимости

CVSS3: 3.7
ubuntu
25 дней назад

ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.

CVSS3: 5.9
redhat
25 дней назад

ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.

CVSS3: 3.7
nvd
25 дней назад

ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory.

CVSS3: 3.7
redos
12 дней назад

Уязвимость ImageMagick

CVSS3: 3.7
redos
12 дней назад

Уязвимость ImageMagick7

EPSS

Процентиль: 14%
0.0023
Низкий