PT-2026-32524 · Unknown+3 · Imagemagick+3

·

CVE-2026-33900

·

Published

2026-04-13

·

Updated

2026-07-30

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 6.9.13-44 ImageMagick versions prior to 7.1.2-19
Description The viff encoder contains an integer truncation or wraparound issue on 32-bit builds. This can trigger an out of bounds heap write, potentially causing a crash.
Recommendations Update to version 6.9.13-44 or later. Update to version 7.1.2-19 or later. As a temporary workaround, consider restricting the use of the viff encoder to minimize the risk of exploitation.

Exploit

Fix

DoS

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-09439
CVE-2026-33900
ECHO-EE9F-E0B6-7A61
GHSA-V67W-737X-V2C9
JLSEC-2026-994
OESA-2026-1916
OESA-2026-1917
OESA-2026-1918
OESA-2026-1919
OESA-2026-1920
OESA-2026-1921
OPENSUSE-SU-2026:10586-1
OPENSUSE-SU-2026:20606-1
SUSE-SU-2026:1596-1
SUSE-SU-2026:1597-1
SUSE-SU-2026:1598-1
SUSE-SU-2026:21380-1
SUSE-SU-2026:2580-1
USN-8558-1

Affected Products

Imagemagick
Linuxmint
Red Os
Ubuntu