CVE-2023-3745: ImageMagick
Medium severity, CVSS 5.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A heap-based buffer overflow issue was found in ImageMagick's PushCharPixel() function in quantum-private.h. This issue may allow a local attacker to trick the user into opening a specially crafted file, triggering an out-of-bounds read error and allowing an application to crash, resulting in a denial of service.
Affected products
- ImageMagick ImageMagick: from 6.0, before 6.9-11-0 (fixed in 6.9-11-0); from 7.0.0-0, before 7.0.10-0 (fixed in 7.0.10-0)
Published 2023-07-24. Last modified 2026-06-17.