Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-61870

Опубликовано: 11 июл. 2026
Источник: debian
EPSS Низкий

Описание

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.26+dfsg1-1package
imagemagickno-dsatrixiepackage

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m596-67p7-69wh

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/fdbf39ba9a681e53e6025d40501ae5a2bfec3000 (7.1.2-26)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/3c574f9ba5387f5f11669fdb4d4e8febc199dca3 (6.9.13-51)

EPSS

Процентиль: 9%
0.00191
Низкий

Связанные уязвимости

CVSS3: 2.9
ubuntu
23 дня назад

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.

CVSS3: 2.9
redhat
23 дня назад

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.

CVSS3: 2.9
nvd
23 дня назад

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the VIFF encoder when memory allocation fails. Attackers can trigger allocation failures by processing specially crafted VIFF images to exhaust available memory and cause denial of service.

suse-cvrf
13 дней назад

Security update for GraphicsMagick

suse-cvrf
12 дней назад

Security update for GraphicsMagick

EPSS

Процентиль: 9%
0.00191
Низкий