Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-28687

Опубликовано: 09 мар. 2026
Источник: redhat
CVSS3: 5.3

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.

A flaw was found in ImageMagick, free and open-source software used for editing and manipulating digital images. A heap use-after-free vulnerability in ImageMagick's MSL (Magick Scripting Language) decoder allows an attacker to trigger access to freed memory by crafting a malicious MSL file. This can lead to a denial of service.

Отчет

MODERATE: This flaw in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by processing a specially crafted MSL file. This could lead to application crashes or potentially arbitrary code execution. Red Hat Enterprise Linux 6 ELS and 7 ELS are affected by this vulnerability.

Меры по смягчению последствий

To reduce the risk of exploitation, avoid processing untrusted or suspicious MSL files with ImageMagick. Implement strict input validation and ensure that ImageMagick only processes files from trusted sources. If ImageMagick is deployed in a server environment, consider isolating the application within a sandboxed environment to limit potential impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2445897ImageMagick: ImageMagick: Heap use-after-free vulnerability allows denial of service via crafted MSL file

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
17 дней назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.

CVSS3: 5.3
nvd
17 дней назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16 and 6.9.13-41, a heap use-after-free vulnerability in ImageMagick's MSL decoder allows an attacker to trigger access to freed memory by crafting an MSL file. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.

CVSS3: 5.3
debian
17 дней назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 5.3
github
15 дней назад

ImageMagick has Heap Use-After-Free in ImageMagick MSL decoder

5.3 Medium

CVSS3