Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-56378

Опубликовано: 21 июн. 2026
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.

A vulnerability in ImageMagick allows attackers to crash the application or expose system data if a maliciously crafted Picture CD (PCD) file is processed.

Отчет

A flaw in ImageMagick's file processing puts applications at risk of service outages or minor data leaks. This is only triggered if the system is forced to process a corrupted, attacker-supplied Picture CD (PCD) file.

Меры по смягчению последствий

Avoid processing untrusted PCD (Picture CD) image files with ImageMagick. Applications that utilize ImageMagick for image processing should ensure that input files originate from trusted sources or are thoroughly validated.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2491158Magick.NET: ImageMagick: Denial of Service and Information Disclosure via crafted PCD file

EPSS

Процентиль: 13%
0.00223
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.7
ubuntu
около 1 месяца назад

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.

CVSS3: 3.7
nvd
около 1 месяца назад

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.

CVSS3: 3.7
debian
около 1 месяца назад

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap ...

CVSS3: 3.7
github
около 1 месяца назад

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.

CVSS3: 8.2
fstec
около 1 месяца назад

Уязвимость консольного графического редактора ImageMagick, связанная с чтением за границами буфера в памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 13%
0.00223
Низкий

4.8 Medium

CVSS3