Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-61464

Опубликовано: 15 июл. 2026
Источник: redhat
EPSS Низкий

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service.

Отчет

Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

Do not use ImageMagick's X11 import command with untrusted window titles. The X11 import functionality requires a running X11 display and is not typically used in server-side image processing pipelines. Upgrade to ImageMagick 7.1.2-26 or 6.9.13-51 mitigates the issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickFix deferred
Red Hat Enterprise Linux 7ImageMagickFix deferred

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=2500894ImageMagick: ImageMagick before 7.1.2-26 Heap Buffer Over-Write via X11

EPSS

Процентиль: 1%
0.00092
Низкий

Связанные уязвимости

CVSS3: 1.8
ubuntu
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service.

CVSS3: 1.8
nvd
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer over-write vulnerability that occurs when running an X11 import with a crafted window title, which can result in heap memory corruption and denial of service.

CVSS3: 1.8
debian
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer ...

suse-cvrf
6 дней назад

Security update for GraphicsMagick

suse-cvrf
6 дней назад

Security update for GraphicsMagick

EPSS

Процентиль: 1%
0.00092
Низкий