Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-64685

Опубликовано: 30 июл. 2026
Источник: debian
EPSS Низкий

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
imagemagickfixed8:7.1.2.27+dfsg1-1package

Примечания

  • https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7rgw-xg25-prjm

  • Fixed by: https://github.com/ImageMagick/ImageMagick/commit/093f476e985d61557ea75ad0ef30d491dff816f3 (7.1.2-27)

EPSS

Процентиль: 10%
0.00197
Низкий

Связанные уязвимости

CVSS3: 5.3
redhat
3 дня назад

A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. A remote attacker could exploit a vulnerability in the BGR decoder by providing a specially crafted image file. This flaw, caused by a missing end-of-file check, can lead to a heap buffer over-read, potentially resulting in the disclosure of sensitive information.

CVSS3: 5.3
nvd
3 дня назад

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-27, the BGR decoder does not check for an end-of-file in every location so a crafted image could result in an heap buffer over-read. This issue has been fixed in version 7.1.2-27.

EPSS

Процентиль: 10%
0.00197
Низкий