Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-61862

Опубликовано: 15 июл. 2026
Источник: debian
EPSS Низкий

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.26+dfsg1-1package
imagemagickno-dsatrixiepackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5ggx

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/4079949bae0cde7e683df2e63c40f2e36f52c1b6 (7.1.2-26)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8 (6.9.13-52)

  • For imagemagick 6 patch include fix for CVE-2026-61863, CVE-2026-61864

EPSS

Процентиль: 1%
0.00105
Низкий

Связанные уязвимости

CVSS3: 2.9
ubuntu
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.

CVSS3: 2.9
redhat
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.

CVSS3: 2.9
nvd
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.

CVSS3: 2.9
github
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.

suse-cvrf
12 дней назад

Security update for ImageMagick

EPSS

Процентиль: 1%
0.00105
Низкий