5.3

CVE-2026-106569

ImageMagick: Denial of service in ASE decoder because of missing security checks

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-32, missing validation and resource checks in the ASE decoder allow a crafted ASE image to cause a crash or a long-running operation. This issue is fixed in version 7.1.2-32.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerImageMagick
≫
Produkt ImageMagick
Version < 7.1.2-32
Status affected
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
security-advisories@github.com 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

CWE-789 Memory Allocation with Excessive Size Value

The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-32
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gwj6-pm7x-3r63
https://github.com/ImageMagick/ImageMagick/commit/0691546106f4c7e8857da9f21a0e4a8f41915388
https://github.com/ImageMagick/ImageMagick/commit/5ecd5b047cee7ccfe4e14a733a0755c7b2a90c7d