Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-62594

Опубликовано: 27 окт. 2025
Источник: redhat
CVSS3: 4.7
EPSS Низкий

Описание

ImageMagick is a software suite to create, edit, compose, or convert bitmap images. ImageMagick versions prior to 7.1.2-8 are vulnerable to denial-of-service due to unsigned integer underflow and division-by-zero in the CLAHEImage function. When tile width or height is zero, unsigned underflow occurs in pointer arithmetic, leading to out-of-bounds memory access, and division-by-zero causes immediate crashes. This issue has been patched in version 7.1.2-8.

A vulnerability in ImageMagick’s CLAHEImage() function (in MagickCore/enhance.c) allows a zero tile width or height to trigger unsigned integer underflow and division-by-zero conditions. When tile_info.height or tile_info.width becomes zero, pointer arithmetic using these values can result in out-of-bounds memory access, memory corruption, or excessive resource consumption, leading to a denial-of-service (DoS).

Отчет

This vulnerability is rated as Moderate because its primary impact is limited to denial-of-service (DoS) rather than data compromise or code execution. Although the flaw involves unsafe pointer arithmetic and division-by-zero conditions, the exploitability is constrained — it requires user interaction or crafted input (e.g., using -clahe 0x0! or very small images) to trigger. The resulting outcome is typically a process crash or resource exhaustion without any proven path to memory corruption exploitation or remote code execution. Moreover, the issue occurs in a non-default processing path (CLAHE filter), reducing its overall exposure. Therefore, despite the presence of out-of-bounds behavior, the lack of confidentiality or integrity impact justifies a Moderate rather than Important severity rating.

Меры по смягчению последствий

No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. The risk can be reduced by disabling or restricting the use of the CLAHE feature in environments that process untrusted images. Administrators can update policy.xml or application logic to block the -clahe option, reject inputs specifying zero or very small tile dimensions, and enforce strict memory and CPU limits on ImageMagick processes.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickFix deferred
Red Hat Enterprise Linux 7ImageMagickFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=2406644ImageMagick: ImageMagick CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS)

EPSS

Процентиль: 3%
0.00014
Низкий

4.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.7
ubuntu
5 месяцев назад

ImageMagick is a software suite to create, edit, compose, or convert bitmap images. ImageMagick versions prior to 7.1.2-8 are vulnerable to denial-of-service due to unsigned integer underflow and division-by-zero in the CLAHEImage function. When tile width or height is zero, unsigned underflow occurs in pointer arithmetic, leading to out-of-bounds memory access, and division-by-zero causes immediate crashes. This issue has been patched in version 7.1.2-8.

CVSS3: 4.7
nvd
5 месяцев назад

ImageMagick is a software suite to create, edit, compose, or convert bitmap images. ImageMagick versions prior to 7.1.2-8 are vulnerable to denial-of-service due to unsigned integer underflow and division-by-zero in the CLAHEImage function. When tile width or height is zero, unsigned underflow occurs in pointer arithmetic, leading to out-of-bounds memory access, and division-by-zero causes immediate crashes. This issue has been patched in version 7.1.2-8.

CVSS3: 4.7
debian
5 месяцев назад

ImageMagick is a software suite to create, edit, compose, or convert b ...

suse-cvrf
5 месяцев назад

Security update for ImageMagick

suse-cvrf
5 месяцев назад

Security update for ImageMagick

EPSS

Процентиль: 3%
0.00014
Низкий

4.7 Medium

CVSS3