Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56361

Опубликовано: 30 июн. 2026
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.

A flaw was found in ImageMagick. An attacker can exploit an off-by-one error in the morphology validation by providing incorrect morphology parameters. This can lead to out-of-bounds heap buffer reads and heap buffer overflow, potentially causing memory access violations.

Отчет

This flaw in ImageMagick is rated as Low impact. An attacker can trigger a memory access violation by submitting a maliciously crafted image. Red Hat has rated this low as there is no impact to the confidentiality of the data and availability is low as denial-of-service is strictly localized to the process handling that specific file.

Меры по смягчению последствий

To reduce exposure, avoid processing untrusted image files with ImageMagick, particularly those that may contain malformed morphology parameters. If processing untrusted content is necessary, consider implementing sandboxing mechanisms to isolate ImageMagick operations and limit the potential blast radius of any successful exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2495418ImageMagick: ImageMagick: Heap buffer overflow via incorrect morphology parameters

EPSS

Процентиль: 3%
0.00128
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 1 месяца назад

ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.

CVSS3: 3.3
nvd
около 1 месяца назад

ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer reads. Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations.

CVSS3: 3.3
debian
около 1 месяца назад

ImageMagick before 7.1.2-19 contains an off-by-one error in morphology ...

CVSS3: 4
redos
7 дней назад

Уязвимость ImageMagick7

CVSS3: 4
redos
7 дней назад

Уязвимость ImageMagick

EPSS

Процентиль: 3%
0.00128
Низкий

3.3 Low

CVSS3