Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56374

Опубликовано: 08 июл. 2026
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure.

A heap buffer overflow vulnerability exists in ImageMagick and Magick.NET's FTXT encoder due to missing boundary checks for the ftxt:format parameter. A remote attacker could exploit this using a specially crafted FTXT image to cause a denial of service or disclose sensitive information.

Отчет

This low-impact heap buffer overflow in ImageMagick's FTXT encoder, caused by insufficient boundary checks, could lead to denial of service or information disclosure if a user opens a specially crafted FTXT file.

Меры по смягчению последствий

To mitigate this, disable the vulnerable FTXT format by adding the following line to your ImageMagick security policy file (typically /etc/ImageMagick-7/policy.xml): Applying this mitigation will immediately block ImageMagick from processing any files in the FTXT format, but requires no service restarts or downtime.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2498106ImageMagick: ImageMagick: Denial of Service and Information Disclosure via heap buffer overflow in FTXT encoder

EPSS

Процентиль: 5%
0.00157
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
27 дней назад

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure.

CVSS3: 3.3
nvd
27 дней назад

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure.

CVSS3: 3.3
debian
27 дней назад

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerabil ...

CVSS3: 4
redos
11 дней назад

Уязвимость ImageMagick7

CVSS3: 3.3
github
27 дней назад

ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary checks when parsing ftxt:format. Remote attackers can trigger an out of bounds read by crafting malicious FTXT image files to cause denial of service or information disclosure.

EPSS

Процентиль: 5%
0.00157
Низкий

3.3 Low

CVSS3