CVE-2026-56378
EUVD-2026-3817421.06.2026, 14:16
ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| imagemagick | imagemagick | 6.9.0-0 ≤ 𝑥 < 6.9.13-40 |
| imagemagick | imagemagick | 7.1.2-0 ≤ 𝑥 < 7.1.2-15 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Amazon Linux Releases
Amazon Package | |||||
|---|---|---|---|---|---|
| ImageMagick |
| ||||
| ImageMagick-c++ |
| ||||
| ImageMagick-c++-debuginfo |
| ||||
| ImageMagick-c++-devel |
| ||||
| ImageMagick-debuginfo |
| ||||
| ImageMagick-debugsource |
| ||||
| ImageMagick-devel |
| ||||
| ImageMagick-doc |
| ||||
| ImageMagick-libs |
| ||||
| ImageMagick-libs-debuginfo |
| ||||
| ImageMagick-perl |
| ||||
| ImageMagick-perl-debuginfo |
|
Common Weakness Enumeration