ImageMagick 7.1.2 RCE: crafted image dimensions chained to heap overflow and system()

evilsocket · x · 2026-09-29

Security researcher @odinshell published a full RCE exploit chain for ImageMagick 7.1.2: crafted .x3f image dimensions trigger an integer overflow, causing an undersized allocation and a controlled heap overflow that smashes a vptr, redirects execution to a fake vtable, and ultimately calls system(). A textbook memory-corruption exploit demo — services processing untrusted images should take note.

Original post →

More from Safety

Safety channel →