CVE 7.6 HIGH

ImageMagick: heap-buffer overflow read in MNG magnification with alpha_CVE-2025-55004

7.6 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.

Basic Information

ID CVE-2025-55004
Source GitHub_M
Published Aug 13, 2025 at 13:59
Modified Aug 13, 2025 at 14:35

Affected Product

Vendor ImageMagick
Product ImageMagick
Version < 7.1.2-1
Affected Versions ImageMagick ImageMagick < 7.1.2-1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.