Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, when a memory allocation fails in the sixel encoder it would be possible to write past the end of a buffer on the stack. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
CVSS vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:HExploitability: 1.4 | Impact: 5.2Attack Vector: Local
Complexity: High
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: None
Integrity: High
Availability: High
Affected Packages3 packages
🔴Vulnerability Details
2OSVCVE-2026-32259: ImageMagick is free and open-source software used for editing and manipulating digital images↗2026-03-12 ▶ CVEListImageMagick has a possible stack buffer overflow in sixel encoder↗2026-03-12 ▶ 📋Vendor Advisories
2Red HatImageMagick: stack-based buffer overflow in sixel encoder↗2026-03-12 ▶ DebianCVE-2026-32259: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...↗2026 ▶ 🕵️Threat Intelligence
1WizCVE-2026-32259 Impact, Exploitability, and Mitigation Steps | Wiz↗ ▶