PT-2026-51513 · Unknown+1 · Imagemagick+1
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
ImageMagick versions prior to 7.1.2-15
ImageMagick versions prior to 6.9.13-40
Description
A heap use-after-free exists in the meta coder. This occurs when memory allocation fails and a single byte is written to a stale pointer. Remote attackers can trigger this condition by processing specially crafted image files, leading to a denial of service. A heap use-after-free is a memory corruption issue where the program continues to use a pointer after the memory it points to has been freed.
Recommendations
Update to version 7.1.2-15 or later.
Update to version 6.9.13-40 or later.
Exploit
Fix
DoS
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Imagemagick
Red Os