We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-53101

ImageMagick has Stack Buffer Overflow in image.c



Description

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal pointer arithmetic to generate an address below the beginning of the stack buffer, resulting in a stack overflow through `vsnprintf()`. Versions 7.1.2-0 and 6.9.13-26 fix the issue.

Reserved 2025-06-25 | Published 2025-07-14 | Updated 2025-07-14 | Assigner GitHub_M


HIGH: 7.4CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H

Problem types

CWE-124: Buffer Underwrite ('Buffer Underflow')

Product status

< 7.1.2-0
affected

< 6.9.13-26
affected

References

github.com/...Magick/security/advisories/GHSA-qh3h-j545-h8c9

github.com/...ommit/66dc8f51c11b0ae1f1cdeacd381c3e9a4de69774

cve.org (CVE-2025-53101)

nvd.nist.gov (CVE-2025-53101)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-53101

Support options

Helpdesk Chat, Email, Knowledgebase