Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46559

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an incorrect check in the JP2 will result in an heap buffer over-write of a single byte when specifying certain options. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. An incorrect check during JPEG 2000 (JP2) image processing, when certain options are specified, can lead to a heap buffer overwrite of a single byte. This vulnerability could allow a local attacker to cause a denial of service (DoS) by crashing the application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2487755ImageMagick: ImageMagick: Denial of service via heap buffer overwrite in JP2 processing

EPSS

Процентиль: 2%
0.00116
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an incorrect check in the JP2 will result in an heap buffer over-write of a single byte when specifying certain options. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

CVSS3: 4
nvd
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, an incorrect check in the JP2 will result in an heap buffer over-write of a single byte when specifying certain options. This issue has been patched in versions 6.9.13-48 and 7.1.2-23.

CVSS3: 4
debian
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 4
github
3 месяца назад

ImageMagick: Heap Buffer Over-Write of a single byte in the JP2 encoder.

CVSS3: 4
fstec
3 месяца назад

Уязвимость декодера формата изображений JP2 консольного графического редактора ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 2%
0.00116
Низкий

6.2 Medium

CVSS3