5.1
CVE-2026-106571
- EPSS -
- Veröffentlicht 07.10.2026 15:28:50
- Zuletzt bearbeitet 07.10.2026 17:16:52
- Erkennungen
ImageMagick: Heap Buffer Over-Write in GetVirtualPixels api will result in a crash
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 6.9.13-56 and 7.1.2-31, a crafted local call to the GetVirtualPixels API can trigger an integer calculation error and write beyond a heap buffer, crashing the server process. This issue is fixed in versions 6.9.13-56 and 7.1.2-31.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerImageMagick
≫
Produkt
ImageMagick
Version
< 6.9.13-56
Status
affected
Version
>= 7.0.0, < 7.1.2-31
Status
affected
VulnDex Vulnerability Enrichment
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| security-advisories@github.com | 5.1 | 1.4 | 3.6 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
|
CWE-190 Integer Overflow or Wraparound
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jvjm-9f73-fhpq
https://github.com/ImageMagick/ImageMagick/commit/8f3a15e60b723bfe3e80bd1b5e4bee88397467f7
https://github.com/ImageMagick/ImageMagick6/commit/91f4ed74a1fd8326ade11a1153de110f22d89aa1
https://github.com/ImageMagick/ImageMagick/releases/tag/7.1.2-31
https://github.com/ImageMagick/ImageMagick6/releases/tag/6.9.13-56