Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-23874

Опубликовано: 20 янв. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-13 have a stack overflow via infinite recursion in MSL (Magick Scripting Language) <write> command when writing to MSL format. Version 7.1.2-13 fixes the issue.

A flaw was found in ImageMagick. A local user could exploit this vulnerability by providing a specially crafted Magick Scripting Language (MSL) file. This file, when processed, could trigger infinite recursion within the <write> command, leading to a stack overflow. Successful exploitation results in a Denial of Service (DoS) condition, making the application unavailable.

Отчет

This vulnerability is rated Moderate for Red Hat products. It affects ImageMagick, where a stack overflow can occur due to infinite recursion when processing a specially crafted Magick Scripting Language (MSL) file. Exploitation requires an attacker to provide a malicious MSL file to a user or service that processes image files using ImageMagick in affected versions of Red Hat Enterprise Linux and Community Projects.

Меры по смягчению последствий

To mitigate this issue, restrict ImageMagick's ability to process Magick Scripting Language (MSL) files. This can be achieved by adding a policy entry to disable the MSL coder. Create or modify the ImageMagick policy file (e.g., /etc/ImageMagick-7/policy.xml or /etc/ImageMagick/policy.xml) to include the following line within the <policymap> tags:

<policy domain="coder" rights="none" pattern="MSL" />

After modifying the policy file, services or applications that use ImageMagick may need to be restarted for the changes to take effect. This may impact functionality that relies on processing MSL files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2431034ImageMagick: ImageMagick: Denial of Service via infinite recursion in MSL <write> command

EPSS

Процентиль: 4%
0.00017
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
2 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-13 have a stack overflow via infinite recursion in MSL (Magick Scripting Language) `<write>` command when writing to MSL format. Version 7.1.2-13 fixes the issue.

CVSS3: 5.5
nvd
2 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-13 have a stack overflow via infinite recursion in MSL (Magick Scripting Language) `<write>` command when writing to MSL format. Version 7.1.2-13 fixes the issue.

CVSS3: 5.5
debian
2 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 5.5
github
2 месяца назад

ImageMagick MSL: Stack overflow via infinite recursion in ProcessMSLScript

CVSS3: 5.5
fstec
2 месяца назад

Уязвимость команды MSL (Magick Scripting Language) <write> консольного графического редактора ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 4%
0.00017
Низкий

5.5 Medium

CVSS3