Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m366-rhm3-cx89

Опубликовано: 08 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 2.1
CVSS3: 3.3

Описание

ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex.

ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex.

EPSS

Процентиль: 9%
0.00189
Низкий

2.1 Low

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 3.3
ubuntu
27 дней назад

ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex.

CVSS3: 3.3
redhat
27 дней назад

ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex.

CVSS3: 3.3
nvd
27 дней назад

ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache updating image channel metadata before pixel cache memory allocation. Attackers can trigger memory and disk allocation failures to cause a heap-buffer-overflow read affecting any writer calling GetPixelIndex.

CVSS3: 3.3
debian
27 дней назад

ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulne ...

suse-cvrf
15 дней назад

Security update for ImageMagick

EPSS

Процентиль: 9%
0.00189
Низкий

2.1 Low

CVSS4

3.3 Low

CVSS3

Дефекты

CWE-125