Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-24485

Опубликовано: 24 фев. 2026
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing the program to become unresponsive and continuously consume CPU resources, ultimately leading to system resource exhaustion and denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

РелизСтатусПримечание
devel

not-affected

7.1.2.18+dfsg1-1
esm-apps/focal

released

8:6.9.10.23+dfsg-2.1ubuntu11.11+esm10
esm-apps/jammy

released

8:6.9.11.60+dfsg-1.3ubuntu0.22.04.5+esm10
esm-apps/noble

released

8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm9
esm-apps/resolute

not-affected

7.1.2.18+dfsg1-1
esm-infra-legacy/trusty

released

8:6.7.7.10-6ubuntu3.13+esm21
esm-infra-legacy/xenial

released

8:6.8.9.9-7ubuntu5.16+esm20
esm-infra/bionic

released

8:6.9.7.4+dfsg-16ubuntu6.15+esm12
esm-infra/xenial

released

8:6.8.9.9-7ubuntu5.16+esm20
jammy

needed

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
5 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing the program to become unresponsive and continuously consume CPU resources, ultimately leading to system resource exhaustion and denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 7.5
nvd
5 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sync marker, causing the program to become unresponsive and continuously consume CPU resources, ultimately leading to system resource exhaustion and denial of service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 7.5
debian
5 месяцев назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 7.5
github
5 месяцев назад

ImageMagick: Infinite loop vulnerability when parsing a PCD file

CVSS3: 7.5
fstec
5 месяцев назад

Уязвимость функции DecodeImage() консольного графического редактора ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3