Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56366

Опубликовано: 10 июл. 2026
Источник: redhat
CVSS3: 3.3

Описание

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.

A flaw was found in ImageMagick. This vulnerability, categorized as a memory leak (CWE-401), occurs in the META reader when processing APP1JPEG input paths. A remote attacker could exploit this by providing specially crafted APP1JPEG image files. Successful exploitation leads to resource exhaustion, resulting in a denial of service (DoS) for the affected system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2498999ImageMagick: ImageMagick: Denial of Service via memory leak in APP1JPEG image processing

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
25 дней назад

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.

CVSS3: 3.3
nvd
25 дней назад

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.

CVSS3: 3.3
debian
25 дней назад

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in th ...

CVSS3: 3.3
github
25 дней назад

ImageMagick before 7.1.2-18 contains a memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion.

suse-cvrf
15 дней назад

Security update for ImageMagick

3.3 Low

CVSS3