Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-61868

Опубликовано: 15 июл. 2026
Источник: debian
EPSS Низкий

Описание

ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.26+dfsg1-1package

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h7f2-f9cc-h2gv

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/808506dc4d0cbf3972ce0d57544a06209b65009c (7.1.2-26)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/875bd8912b3b54a58e09c14085cf2b14a478a86b (6.9.13-51)

EPSS

Процентиль: 13%
0.00222
Низкий

Связанные уязвимости

CVSS3: 3.7
redhat
19 дней назад

A flaw was found in ImageMagick. A remote attacker could exploit a memory leak in the YUV decoder when processing a specially crafted image file. Repeatedly triggering this flaw can lead to resource exhaustion, resulting in a denial of service for the application.

CVSS3: 3.7
nvd
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).

CVSS3: 3.7
github
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).

EPSS

Процентиль: 13%
0.00222
Низкий