Executive brief
ImageMagick is a popular software suite used for editing and converting digital images. A vulnerability exists when the software attempts to import images from an X11 window system using a specially crafted window title. If exploited, this could cause the application to crash, leading to a denial of service, though it requires high privileges and specific user interaction to execute.
Technical details
A heap-based buffer overflow (CWE-122) exists in ImageMagick's X11 import component. The vulnerability is triggered when the application processes an X11 window with a maliciously crafted title, leading to a heap-based buffer overwrite. Exploitation requires local access, high privileges, and user interaction, making the attack complexity high. Successful exploitation results in heap memory corruption and a denial of service (DoS). The issue is resolved in versions 7.1.2-26 and 6.9.13-51.
Affected products
- ImageMagick ImageMagick < 7.1.2-26, < 6.9.13-51
Timeline
- 2026-06-26: advisory: GitHub Security Advisory published
- 2026-07-15: disclosed: NVD publication date