Executive brief
ImageMagick is a widely used software suite for displaying, converting, and editing image files. A vulnerability in its MNG image format decoder could allow an attacker to view fragments of sensitive data from the computer's memory. This occurs because the software fails to properly clear memory before using it, potentially exposing information from previous operations to unauthorized parties.
Technical details
An information disclosure vulnerability exists in the ImageMagick MNG decoder (specifically affecting Magick.NET implementations). The root cause is a failure to properly initialize or clear allocated heap memory, leaving a portion of the pixel data unchanged from its previous state in memory. A remote, unauthenticated attacker can exploit this by providing a specially crafted MNG file for processing, which could result in the disclosure of sensitive fragments of heap memory. The vulnerability is addressed in Magick.NET version 14.15.0.
Affected products
- ImageMagick Magick.NET-Q16-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-OpenMP-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-x86 < 14.15.0
- ImageMagick Magick.NET-Q16-OpenMP-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-OpenMP-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-arm64 < 14.15.0
- ImageMagick Magick.NET-Q16-x64 < 14.15.0
- ImageMagick Magick.NET-Q16-x86 < 14.15.0
- ImageMagick Magick.NET-Q8-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q8-OpenMP-arm64 < 14.15.0
- ImageMagick Magick.NET-Q8-OpenMP-x64 < 14.15.0
- ImageMagick Magick.NET-Q8-arm64 < 14.15.0
- ImageMagick Magick.NET-Q8-x64 < 14.15.0
- ImageMagick Magick.NET-Q8-x86 < 14.15.0
Timeline
- 2026-06-26: disclosed: Initial disclosure by dlemstra
- 2026-07-01: advisory: NVD publication date
- 2026-07-23: advisory: GitHub Advisory published