Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56370

Опубликовано: 24 июн. 2026
Источник: redhat
CVSS3: 3.3

Описание

ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential code execution.

An out-of-bounds access vulnerability exists in ImageMagick's ConnectedComponentsImage() function. By passing malformed connected-components definitions through the CLI, an attacker can cause a denial of service or potentially execute arbitrary code.

Отчет

An out-of-bounds access flaw exists in ImageMagick when handling malformed connected-components artifacts. Exploitation requires local user interaction via the CLI and can result in a denial of service or arbitrary code execution.

Меры по смягчению последствий

Prevent the injection of malformed -connected-components flags by strictly sanitizing all user-supplied CLI input in backend applications. Additionally, if automated ImageMagick processing is not required, restrict execution permissions on the binaries to trusted administrative groups.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=2492143Imagemagick: ImageMagick - Out-of-bounds Access in ConnectedComponentsImage via connected-components Artifact

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 1 месяца назад

ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential code execution.

CVSS3: 3.3
nvd
около 1 месяца назад

ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger access violations by specifying malformed connected-components definitions via CLI, causing denial of service or potential code execution.

CVSS3: 3.3
debian
около 1 месяца назад

ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerabi ...

CVSS3: 4
redos
24 дня назад

Уязвимость ImageMagick

CVSS3: 4
redos
24 дня назад

Уязвимость ImageMagick7

3.3 Low

CVSS3