Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53464

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, when providing invalid options to the wand option parser a small memory leak will occur. This issue has been patched in version 7.1.2-25.

A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. A local user could exploit this vulnerability by providing invalid options to the wand option parser, which would cause a small memory leak. This memory leak could lead to a Denial of Service (DoS) due to resource exhaustion.

Отчет

This flaw in ImageMagick is rated as Low impact. A local attacker could trigger a small memory leak by providing specially crafted invalid options to the wand option parser. While this could potentially lead to a denial of service due to resource exhaustion, the attack requires local access and specific user interaction, limiting its overall impact on Red Hat products.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2487768ImageMagick: ImageMagick: Memory leak via invalid options to wand option parser

EPSS

Процентиль: 2%
0.00111
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 4
ubuntu
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, when providing invalid options to the wand option parser a small memory leak will occur. This issue has been patched in version 7.1.2-25.

CVSS3: 4
nvd
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, when providing invalid options to the wand option parser a small memory leak will occur. This issue has been patched in version 7.1.2-25.

CVSS3: 4
debian
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 4
github
около 1 месяца назад

ImageMagick: Memory Leak in wand option parser when providing invalid arguments

CVSS3: 4
fstec
около 2 месяцев назад

Уязвимость консольного графического редактора ImageMagick, связанная с отсутствием освобождения памяти после эффективного срока службы, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 2%
0.00111
Низкий

3.3 Low

CVSS3