Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46521

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

A flaw was found in ImageMagick. When processing an image with LZMA compression in the MIFF encoder, a missing check can lead to an out-of-bounds write. This vulnerability could allow an attacker to cause a denial of service (DoS) by providing a specially crafted image file, leading to application instability or crashes.

Отчет

This Moderate impact flaw in ImageMagick allows an out-of-bounds write when processing specially crafted image files using LZMA compression within the MIFF encoder. While requiring user interaction to process a malicious image, this vulnerability could lead to a denial of service, causing application instability or crashes in Red Hat products that utilize ImageMagick for image manipulation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2487766ImageMagick: ImageMagick: Denial of Service via out-of-bounds write in LZMA MIFF encoder

EPSS

Процентиль: 2%
0.00111
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

CVSS3: 5.5
nvd
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the MIFF encoder an out of bounds write can occur due to a missing check. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

CVSS3: 5.5
debian
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 5.5
github
3 месяца назад

ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression

CVSS3: 5.5
fstec
3 месяца назад

Уязвимость кодировщика MIFF консольного графического редактора ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 2%
0.00111
Низкий

5.5 Medium

CVSS3