ImageMagick has a heap overflow caused by integer overflow/wraparound in viff encoder on 32-bit builds
Moderate severity
GitHub Reviewed
Published
Apr 13, 2026
in
ImageMagick/ImageMagick
•
Updated Apr 24, 2026
Description
Published to the GitHub Advisory Database
Apr 13, 2026
Reviewed
Apr 13, 2026
Published by the National Vulnerability Database
Apr 13, 2026
Last updated
Apr 24, 2026
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions below both 7.1.2-19 and 6.9.13-44, the viff encoder contains an integer truncation/wraparound issue on 32-bit builds that could trigger an out of bounds heap write, potentially causing a crash. This issue has been fixed in versions 6.9.13-44 and 7.1.2-19.
References