PT-2026-107985 · Imagemagick · Imagemagick
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
ImageMagick before 6.9.13-55 and 7.x before 7.1.2-30 contains a security policy bypass in the MAT decoder, which does not enforce configured temporary file size limits when reading highly compressed data. Attackers can supply a crafted MAT image whose decompressed data is written to temporary files larger than the policy allows, consuming disk resources.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imagemagick