Home

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.

PUBLISHED Reserved 2025-08-04 | Published 2025-08-13 | Updated 2025-08-13 | Assigner GitHub_M




HIGH: 7.6CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

Problem types

CWE-122: Heap-based Buffer Overflow

Product status

< 7.1.2-1
affected

References

github.com/...Magick/security/advisories/GHSA-cjc8-g9w8-chfw

goo.gle/bigsleep

cve.org (CVE-2025-55004)

nvd.nist.gov (CVE-2025-55004)

Download JSON