CVE-2026-27799 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read…
Medium CVSS: 4.0

CVE-2026-27799

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in the DJVU image format handler. The vulnerability occurs due to integer truncation when calculating the stride (row size) for pixel buffer allocation. The stride calculation overflows a 32-bit signed integer, resulting in an out-of-bounds memory reads. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
Vendor
Imagemagick
Product
Imagemagick
CWE
CWE-122
Yayın Tarihi
2026-02-26 00:16:25
Güncelleme
2026-02-27 16:01:02
Source Identifier
security-advisories@github.com
KEV Date Added
-

Kategoriler

Referanslar