Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-61871

Опубликовано: 15 июл. 2026
Источник: debian
EPSS Низкий

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.26+dfsg1-1package

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h58x-r7f7-rh84

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/b237a4fa9cbffcb11ee579d386fd37c570d5dffe (7.1.2-26)

  • Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/e4b68bfb6a9541a9c3a4af81a21bf0c253661083 (6.9.13-51)

EPSS

Процентиль: 14%
0.00232
Низкий

Связанные уязвимости

CVSS3: 3.7
redhat
19 дней назад

A flaw was found in ImageMagick. A remote attacker could exploit a memory leak in the ICON decoder by providing a specially crafted ICON file. When the file is processed, a memory allocation failure occurs, leading to memory exhaustion. This can result in a denial of service (DoS), making the affected system or application unavailable.

CVSS3: 3.7
nvd
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.

CVSS3: 3.7
github
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of service.

EPSS

Процентиль: 14%
0.00232
Низкий