Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-62946

Опубликовано: 30 июл. 2026
Источник: redhat
CVSS3: 5.1
EPSS Низкий

Описание

A flaw was found in ImageMagick. When processing extremely large JNX image files on 32-bit systems, an attacker could trigger an integer overflow. This overflow leads to a heap buffer over-write, which can cause the application to crash, resulting in a denial of service.

Отчет

This Moderate impact flaw in ImageMagick affects 32-bit systems, where processing an exceptionally large JNX image file can trigger an integer overflow. This leads to a heap buffer overwrite, causing a denial of service. The vulnerability requires local access and has high attack complexity, limiting its broader exploitability.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted JNX image files with ImageMagick on 32-bit systems. Restricting ImageMagick's exposure to untrusted or excessively large JNX files can reduce the risk of a denial of service.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2508878Imagemagick: ImageMagick: Denial of Service via integer overflow in JNX decoder on 32-bit systems

EPSS

Процентиль: 3%
0.00132
Низкий

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.1
ubuntu
4 дня назад

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52 and 7.1.2-27.

CVSS3: 5.1
nvd
5 дней назад

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to both 6.9.13-52 and 7.1.2-27, processing an extremely large JNX file on 32-bit platforms can cause an integer overflow, leading to a heap buffer over-write. This issue has been fixed in versions 6.9.13-52 and 7.1.2-27.

CVSS3: 5.1
debian
5 дней назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 5.1
github
10 дней назад

ImageMagick: Integer Overflow in JNX decoder causes heap buffer over-write when processing extremly large files on 32-bit builds

suse-cvrf
4 дня назад

Security update for ImageMagick

EPSS

Процентиль: 3%
0.00132
Низкий

5.1 Medium

CVSS3