Medium severity6.5NVD Advisory· Published Feb 24, 2022· Updated Jun 17, 2026
CVE-2021-3596
CVE-2021-3596
Description
A NULL pointer dereference flaw was found in ImageMagick in versions prior to 7.0.10-31 in ReadSVGImage() in coders/svg.c. This issue is due to not checking the return value from libxml2's xmlCreatePushParserCtxt() and uses the value directly, which leads to a crash and segmentation fault.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6(expand)+ 1 more
- (no CPE)
- (no CPE)range: <7.0.10-31
- osv-coords4 versionspkg:apk/chainguard/imagemagick-6pkg:apk/chainguard/imagemagick-6-devpkg:apk/chainguard/imagemagick-6-docpkg:apk/chainguard/imagemagick-6-static
< 0+ 3 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
Patches
Vulnerability mechanics
References
4- github.com/ImageMagick/ImageMagick/issues/2624nvdExploitIssue TrackingThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- lists.debian.org/debian-lts-announce/2022/05/msg00018.htmlnvdMailing ListThird Party Advisory
- lists.debian.org/debian-lts-announce/2023/03/msg00008.htmlnvd
News mentions
0No linked articles in our index yet.