Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-68469

Опубликовано: 18 дек. 2025
Источник: redhat
CVSS3: 3.3
EPSS Низкий

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.

A flaw was found in ImageMagick. Processing a specially crafted TIFF file can cause a heap-based buffer overflow and result in a denial of service.

Отчет

To exploit this issue, an attacker needs to convince a user to process a crafted TIFF file with ImageMagick. Additionally, this vulnerability can cause a heap-based buffer overflow, but there is no evidence of memory corruption or code execution, limiting the impact to an application crash. Due to these reasons, this flaw has been rated with a low severity.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted TIFF files with ImageMagick. In environments where ImageMagick processes files automatically, ensure that all input files originate from trusted sources or implement strict input validation to prevent the processing of malicious TIFF files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2423598ImageMagick: heap-based buffer overflow via a crafted TIFF file

EPSS

Процентиль: 8%
0.00028
Низкий

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
4 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.

CVSS3: 3.3
nvd
4 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.

CVSS3: 3.3
debian
4 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

suse-cvrf
3 месяца назад

Security update for ImageMagick

CVSS3: 3.3
github
7 месяцев назад

ImageMagick has a heap-buffer-overflow

EPSS

Процентиль: 8%
0.00028
Низкий

3.3 Low

CVSS3