CVE-2019-11470: ImageMagick
Medium severity, CVSS 6.5. EPSS: 3.6% chance of exploitation in the next 30 days.
The cineon parsing component in ImageMagick 7.0.8-26 Q16 allows attackers to cause a denial-of-service (uncontrolled resource consumption) by crafting a Cineon image with an incorrect claimed image size. This occurs because ReadCINImage in coders/cin.c lacks a check for insufficient image data in a file.
Affected products
- ImageMagick ImageMagick: version 7.0.8-26 only
Published 2019-04-23. Last modified 2026-06-17.