Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48994

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 5.9
EPSS Низкий

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

A flaw was found in ImageMagick. A missing check of a return value in the MAT decoder on 32-bit systems could lead to a heap buffer over-write. This vulnerability may allow an attacker to cause a denial of service.

Отчет

This Moderate impact flaw in ImageMagick could lead to a denial of service on 32-bit systems when processing a maliciously crafted MAT image file. The vulnerability arises from a missing return value check in the MAT decoder, which could result in a heap buffer over-write. Exploitation requires an attacker to provide a specially crafted image to a system running ImageMagick.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-253
https://bugzilla.redhat.com/show_bug.cgi?id=2487771ImageMagick: ImageMagick: Denial of Service via heap buffer over-write in MAT decoder

EPSS

Процентиль: 14%
0.00227
Низкий

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.9
ubuntu
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

CVSS3: 5.9
nvd
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer over-write in the MAT decoder on 32-bit systems. This issue has been patched in versions 6.9.13-48 and 7.1.2-24.

CVSS3: 5.9
debian
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 5.9
redos
23 дня назад

Уязвимость ImageMagick

CVSS3: 5.9
redos
23 дня назад

Уязвимость ImageMagick7

EPSS

Процентиль: 14%
0.00227
Низкий

5.9 Medium

CVSS3