Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-25576

Опубликовано: 24 фев. 2026
Источник: redhat
CVSS3: 5.1

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in multiple raw image format handles. The vulnerability occurs when processing images with -extract dimensions larger than -size dimensions, causing out-of-bounds memory reads from a heap-allocated buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. This heap buffer over-read vulnerability occurs when processing images where the -extract dimensions are larger than the -size dimensions, causing out-of-bounds memory reads from a heap-allocated buffer. A remote attacker could exploit this vulnerability to potentially disclose sensitive information.

Отчет

This MODERATE impact vulnerability in ImageMagick is due to a heap buffer over-read when processing images with -extract dimensions larger than -size dimensions. This flaw could lead to out-of-bounds memory reads from a heap-allocated buffer. Red Hat Enterprise Linux and Community Projects are affected if ImageMagick is used to process untrusted image data with these specific parameters.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted or malformed image files with ImageMagick. Users should exercise caution when handling images from untrusted sources.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2442093ImageMagick: ImageMagick: Information disclosure due to heap buffer over-read when processing malformed images

5.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.1
ubuntu
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in multiple raw image format handles. The vulnerability occurs when processing images with -extract dimensions larger than -size dimensions, causing out-of-bounds memory reads from a heap-allocated buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 5.1
nvd
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in multiple raw image format handles. The vulnerability occurs when processing images with -extract dimensions larger than -size dimensions, causing out-of-bounds memory reads from a heap-allocated buffer. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 5.1
debian
около 1 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 5.1
github
около 1 месяца назад

ImageMagick: Out of bounds read in multiple coders read raw pixel data

suse-cvrf
19 дней назад

Security update for ImageMagick

5.1 Medium

CVSS3