Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48734

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 5.5

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result in a stack overflow due to a missing depth or visited-set check. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.

A flaw was found in ImageMagick. A remote attacker could exploit this vulnerability by tricking a user into processing a specially crafted MVG (Magick Vector Graphics) file. This could lead to a stack overflow due to a missing depth or visited-set check, resulting in a denial of service (DoS) for the affected system.

Отчет

This Moderate-severity flaw in ImageMagick requires user interaction, as an attacker must trick a user into processing a specially crafted MVG file. Successful exploitation could lead to a denial of service due to a stack overflow, impacting the availability of systems processing untrusted image data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2487756ImageMagick: ImageMagick: Denial of Service via crafted MVG file leading to stack overflow

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result in a stack overflow due to a missing depth or visited-set check. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.

CVSS3: 5.5
nvd
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result in a stack overflow due to a missing depth or visited-set check. This issue has been patched in versions 6.9.13-49 and 7.1.2-24.

CVSS3: 5.5
debian
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 5.5
github
около 1 месяца назад

ImageMagick Vulnerable to Stack Overflow in its MVG Decoder

CVSS3: 5.5
fstec
2 месяца назад

Уязвимость консольного графического редактора ImageMagick, связанная с неконтролируемой рекурсией, позволяющая нарушителю вызвать отказ в обслуживании

5.5 Medium

CVSS3