ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2.
Metrics
Affected Vendors & Products
References
History
Thu, 22 Jan 2026 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing <comment> tags before images are loaded. This can lead to DoS attack due to assertion failure (debug builds) or NULL pointer dereference (release builds). This issue is fixed in version 14.10.2. | |
| Title | ImageMagick has a NULL pointer dereference in MSL parser via <comment> tag before image load | |
| Weaknesses | CWE-476 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-22T00:32:52.908Z
Reserved: 2026-01-19T14:49:06.312Z
Link: CVE-2026-23952
No data.
Status : Received
Published: 2026-01-22T01:15:52.790
Modified: 2026-01-22T01:15:52.790
Link: CVE-2026-23952
No data.
OpenCVE Enrichment
No data.