Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-61862

Опубликовано: 15 июл. 2026
Источник: redhat
CVSS3: 2.9

Описание

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.

A flaw was found in ImageMagick. When a user displays an image profile using the identify command with debug output enabled, a vulnerability allows for information disclosure. This occurs due to an out-of-bounds read, where a single byte beyond the profile's boundary can be unintentionally printed. This could potentially expose sensitive data.

Отчет

Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

Do not enable debug output when processing untrusted image files with ImageMagick's identify command. Debug output is not enabled by default and is only used for diagnostic purposes. Upgrade to ImageMagick 7.1.2-26 or 6.9.13-51 mitigates the issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickFix deferred
Red Hat Enterprise Linux 7ImageMagickFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2500933ImageMagick: ImageMagick: Information disclosure via out-of-bounds read when displaying profiles with debug enabled

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 2.9
ubuntu
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.

CVSS3: 2.9
nvd
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.

CVSS3: 2.9
debian
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disc ...

CVSS3: 2.9
github
19 дней назад

ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disclosure vulnerability: when a profile is displayed with the identify command and the profile value is not printable, a single byte at the end of the profile can be printed (read past the profile boundary). This behavior occurs when debug output is enabled.

suse-cvrf
12 дней назад

Security update for ImageMagick

2.9 Low

CVSS3