ImageMagick Vulnerability Allows Remote Denial of Service
Summary
CERT-Bund has issued a security advisory for ImageMagick, detailing a vulnerability that allows remote denial of service attacks. The advisory affects versions prior to Open Source ImageMagick <7.1.2-17 and <6.9.13-42, impacting Linux, UNIX, and Windows systems.
What changed
CERT-Bund has released security advisory WID-SEC-2026-0744 concerning a critical vulnerability in ImageMagick. This vulnerability, with a CVSS Base Score of 5.3, allows remote, anonymous attackers to execute a denial of service (DoS) attack. The advisory specifically impacts Open Source ImageMagick versions prior to 7.1.2-17 and 6.9.13-42, affecting Linux, UNIX, and Windows operating systems.
Organizations utilizing affected versions of ImageMagick should immediately update to a patched version or implement available mitigations to prevent potential DoS attacks. Failure to address this vulnerability could lead to service disruptions and impact the availability of systems processing graphics. While no specific compliance deadline is mentioned, prompt action is recommended to secure systems.
What to do next
- Update ImageMagick to a version later than 7.1.2-17 or 6.9.13-42
- Implement available mitigations for ImageMagick DoS vulnerability
Source document (simplified)
[WID-SEC-2026-0744] ImageMagick: Schwachstelle ermöglicht Denial of Service CVSS Base Score 5.3 (mittel) CVSS Temporal Score 4.6 (mittel) Remoteangriff ja Datum 16.03.2026 Stand 17.03.2026 Mitigation ja
Betroffene Systeme
Betriebssystem
- Linux
- Sonstiges
- UNIX
- Windows
Produktbeschreibung
ImageMagick ist eine Sammlung von Programmbibliotheken und Werkzeugen, die Grafiken in zahlreichen Formaten verarbeiten kann.
Produkte
16.03.2026
- Open Source ImageMagick <7.1.2-17
- Open Source ImageMagick <6.9.13-42
Angriff
Angriff
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in ImageMagick ausnutzen, um einen Denial of Service Angriff durchzuführen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Related changes
Source
Classification
Who this affects
Taxonomy
Browse Categories
Get Data Privacy & Cybersecurity alerts
Weekly digest. AI-summarized, no noise.
Free. Unsubscribe anytime.
Get alerts for this source
We'll email you when CERT-Bund Security Advisories publishes new changes.