Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-69204

Опубликовано: 30 дек. 2025
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and caused a DoS attack. Version 7.1.2-12 fixes the issue.

A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. A remote attacker can exploit this vulnerability by providing a specially crafted SVG (Scalable Vector Graphics) image. An integer overflow occurs in the WriteSVGImage function when storing number_attributes, which subsequently triggers a buffer overflow. This can lead to a Denial of Service (DoS) attack, making the software unavailable.

Отчет

This vulnerability is rated Moderate for Red Hat products as it can lead to a Denial of Service in ImageMagick. A remote attacker can exploit this flaw by providing a specially crafted SVG image, triggering an integer overflow and subsequent buffer overflow during image processing. This can render the ImageMagick software unavailable.

Меры по смягчению последствий

To mitigate this issue, users should avoid processing untrusted SVG images with ImageMagick. If processing untrusted content is unavoidable, consider isolating ImageMagick operations within a sandboxed environment to limit potential impact.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2426294ImageMagick: ImageMagick: Denial of Service via integer overflow in SVG image processing

EPSS

Процентиль: 41%
0.00524
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
7 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and caused a DoS attack. Version 7.1.2-12 fixes the issue.

CVSS3: 5.3
nvd
7 месяцев назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and caused a DoS attack. Version 7.1.2-12 fixes the issue.

CVSS3: 5.3
debian
7 месяцев назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 5.3
fstec
7 месяцев назад

Уязвимость функции WriteSVGImage консольного графического редактора ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
redos
около 2 месяцев назад

Уязвимость ImageMagick

EPSS

Процентиль: 41%
0.00524
Низкий

5.3 Medium

CVSS3