Executive brief
ImageMagick is a software suite used for creating, editing, and converting images. A vulnerability exists where processing a specifically crafted window title during an X11 screen capture can cause a memory error. This could lead to a minor service disruption or application crash, though it requires high privileges and specific user interaction to exploit.
Technical details
A heap-based buffer overflow (CWE-122) exists in ImageMagick's X11 import component. The vulnerability is triggered when the application processes a crafted window title during an import operation, leading to a heap buffer overwrite. Exploitation requires local access, high privileges, and user interaction, with a high attack complexity. The impact is limited to a partial loss of availability (DoS). The issue is addressed in Magick.NET version 14.15.0.
Affected products
- ImageMagick Magick.NET-Q16-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q16-HDRI-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q8-AnyCPU < 14.15.0
- ImageMagick Magick.NET-Q16-x64 < 14.15.0
Timeline
- 2026-06-26: disclosed
- 2026-06-26: patched: Magick.NET 14.15.0 released
- 2026-07-24: advisory