ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy bypass vulnerability in LoadPolicyCache that silently skips security policy rules when policy.xml uses an alternate DOCTYPE. A valid DOCTYPE not ending in '' makes the parser consume the rest of the file, so no policy rules are applied and restricted operations become allowed...
Vulnerability
Vulners
Apply vendor security patch