Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-27799

Опубликовано: 25 фев. 2026
Источник: redhat
CVSS3: 4

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The vulnerability occurs due to integer truncation when calculating the stride (row size) for pixel buffer allocation. The stride calculation overflows a 32-bit signed integer, resulting in an out-of-bounds memory reads. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

A flaw was found in ImageMagick, a software suite used for editing and manipulating digital images. This vulnerability, a heap buffer over-read, exists within the component that handles DJVU image files. A local attacker could exploit this by processing a specially crafted DJVU image, leading to an error where the software miscalculates memory allocation due to an integer truncation. This causes the software to attempt to read memory outside its designated boundaries, which can result in a denial of service or potentially corrupt data.

Отчет

This MODERATE impact vulnerability in ImageMagick involves a heap buffer over-read within the DJVU image format handler. The flaw occurs due to an integer truncation during stride calculation for pixel buffer allocation, leading to out-of-bounds memory reads when processing a specially crafted DJVU image. Red Hat Enterprise Linux 6 ELS and 7 ELS are affected.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted DJVU image files with ImageMagick. For server deployments, restrict network access to services that use ImageMagick for image processing. As an additional measure, consider disabling the DJVU delegate in ImageMagick's policy.xml configuration to prevent the processing of DJVU files. This may impact functionality that relies on DJVU image support.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2442879ImageMagick: ImageMagick: Denial of Service and data corruption due to crafted DJVU image processing

4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
30 дней назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The vulnerability occurs due to integer truncation when calculating the stride (row size) for pixel buffer allocation. The stride calculation overflows a 32-bit signed integer, resulting in an out-of-bounds memory reads. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 4
nvd
30 дней назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The vulnerability occurs due to integer truncation when calculating the stride (row size) for pixel buffer allocation. The stride calculation overflows a 32-bit signed integer, resulting in an out-of-bounds memory reads. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 4
debian
30 дней назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 4
github
около 1 месяца назад

ImageMagick has a heap Buffer Over-read in its DJVU image format handler

CVSS3: 4.4
fstec
около 1 месяца назад

Уязвимость консольного графического редактора ImageMagick, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю оказать воздействие на целостность и доступность защищаемой информации

4 Medium

CVSS3