{"id":"GHSA-8g9f-ccmr-vfvg","summary":"Duplicate Advisory: ImageMagick has a possible heap Use After Free vulnerability in its meta coder","details":"### Duplicate Advisory\nThis advisory has been withdrawn because it is a duplicate of GHSA-2gq3-ww97-wfjm. This link is maintained to preserve external references.\n\n### Original Description\nImageMagick before 7.1.2-15 and 6.9.13-40 contains a heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. Remote attackers can trigger it by processing specially crafted image files, causing a denial of service.","modified":"2026-09-24T20:15:05.858681633Z","published":"2026-06-23T15:32:37Z","withdrawn":"2026-09-24T20:03:43Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-09-24T20:03:43Z","nvd_published_at":"2026-06-23T13:16:46Z","cwe_ids":["CWE-416"],"severity":"MODERATE"},"references":[{"type":"WEB","url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-2gq3-ww97-wfjm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56376"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/imagemagick-heap-use-after-free-in-meta-coder"}],"affected":[{"package":{"name":"Magick.NET-Q16-AnyCPU","ecosystem":"NuGet","purl":"pkg:nuget/Magick.NET-Q16-AnyCPU"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"14.10.3"}]}],"versions":["10.0.0","10.1.0","11.0.0","11.1.0","11.1.1","11.1.2","11.2.0","11.2.1","11.3.0","12.0.0","12.0.1","12.1.0","12.2.0","12.2.1","12.2.2","12.3.0","13.0.0","13.0.1","13.1.0","13.1.1","13.1.2","13.1.3","13.10.0","13.2.0","13.3.0","13.4.0","13.5.0","13.6.0","13.7.0","13.8.0","13.9.0","13.9.1","14.0.0","14.1.0","14.10.0","14.10.1","14.10.2","14.2.0","14.3.0","14.4.0","14.5.0","14.6.0","14.7.0","14.8.0","14.8.1","14.8.2","14.9.0","14.9.1","6.8.8.1001","6.8.9.1","6.8.9.101","6.8.9.2","6.8.9.401","6.8.9.501","6.8.9.601","7.0.0.1","7.0.0.10","7.0.0.101","7.0.0.102","7.0.0.103","7.0.0.104","7.0.0.11","7.0.0.12","7.0.0.13","7.0.0.14","7.0.0.15","7.0.0.16","7.0.0.17","7.0.0.18","7.0.0.19","7.0.0.2","7.0.0.20","7.0.0.21","7.0.0.22","7.0.0.3","7.0.0.4","7.0.0.5","7.0.0.6","7.0.0.7","7.0.0.8","7.0.0.9","7.0.1","7.0.1.100","7.0.1.101","7.0.1.500","7.0.2.100","7.0.2.400","7.0.2.600","7.0.2.900","7.0.2.901","7.0.2.902","7.0.3","7.0.3.1","7.0.3.300","7.0.3.500","7.0.3.501","7.0.3.502","7.0.3.901","7.0.3.902","7.0.4.100","7.0.4.400","7.0.4.700","7.0.4.701","7.0.5.500","7.0.5.501","7.0.5.502","7.0.5.800","7.0.5.900","7.0.6","7.0.6.100","7.0.6.1000","7.0.6.1001","7.0.6.1002","7.0.6.101","7.0.6.102","7.0.6.600","7.0.6.601","7.0.7","7.0.7.300","7.0.7.700","7.0.7.900","7.1.0","7.10.0","7.10.1","7.10.2","7.11.0","7.11.1","7.12.0","7.13.0","7.13.1","7.14.0","7.14.0.1","7.14.0.2","7.14.0.3","7.14.1","7.14.2","7.14.3","7.14.4","7.14.5","7.15.0","7.15.0.1","7.15.1","7.15.2","7.15.3","7.15.4","7.15.5","7.16.0","7.16.1","7.17.0","7.17.0.1","7.18.0","7.19.0","7.19.0.1","7.2.0","7.2.1","7.20.0","7.20.0.1","7.21.0","7.21.1","7.22.0","7.22.1","7.22.2","7.22.2.1","7.22.2.2","7.22.3","7.23.0","7.23.1","7.23.2","7.23.2.1","7.23.3","7.23.4","7.24.0","7.24.1","7.3.0","7.4.0","7.4.1","7.4.2","7.4.3","7.4.4","7.4.5","7.4.6","7.5.0","7.5.0.1","7.6.0","7.6.0.1","7.7.0","7.8.0","7.9.0","7.9.0.1","7.9.0.2","7.9.1","7.9.2","8.0.0","8.0.1","8.1.0","8.2.0","8.2.1","8.3.0","8.3.1","8.3.2","8.3.3","8.4.0","8.5.0","8.6.0","8.6.1","9.0.0","9.1.0","9.1.1","9.1.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-8g9f-ccmr-vfvg/GHSA-8g9f-ccmr-vfvg.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}