Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53465

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 6.2
EPSS Низкий

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap buffer over-write when encoding it with the SF3 encoder. This issue has been patched in version 7.1.2-25.

A flaw was found in ImageMagick. An attacker can exploit this vulnerability by providing a specially crafted multi-frame image. This can lead to a heap buffer overwrite when the image is encoded with the SF3 encoder, resulting in a denial of service (DoS) for the affected system.

Отчет

Moderate: A heap buffer overwrite flaw in ImageMagick's SF3 encoder can lead to a denial of service when processing a specially crafted multi-frame image. This vulnerability requires local access to the system for exploitation, but does not require user interaction once an attacker can provide the malicious input.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2487772ImageMagick: ImageMagick: Denial of Service via crafted multi-frame image leading to heap buffer overwrite

EPSS

Процентиль: 2%
0.00113
Низкий

6.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.2
ubuntu
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap buffer over-write when encoding it with the SF3 encoder. This issue has been patched in version 7.1.2-25.

CVSS3: 6.2
nvd
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap buffer over-write when encoding it with the SF3 encoder. This issue has been patched in version 7.1.2-25.

CVSS3: 6.2
debian
около 2 месяцев назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 6.2
redos
23 дня назад

Уязвимость ImageMagick7

CVSS3: 6.2
redos
23 дня назад

Уязвимость ImageMagick

EPSS

Процентиль: 2%
0.00113
Низкий

6.2 Medium

CVSS3