Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-25799

Опубликовано: 24 фев. 2026
Источник: redhat
CVSS3: 5.3

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image loading, resulting in a reliable denial-of-service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

A flaw was found in ImageMagick, a free and open-source software used for editing and manipulating digital images. A logic error in the YUV sampling factor validation allows an invalid sampling factor to bypass security checks. This can trigger a division-by-zero error during image loading, leading to a reliable Denial of Service (DoS) for an affected system when processing a specially crafted image.

Отчет

This MODERATE impact vulnerability in ImageMagick can lead to a denial-of-service. A logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks, triggering a division-by-zero during image loading. This affects ImageMagick as shipped in Red Hat Enterprise Linux 6 ELS and 7 ELS.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted or unknown image files with ImageMagick. Limiting the exposure of ImageMagick to untrusted input sources can reduce the risk of exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=2442120ImageMagick: ImageMagick: Denial of Service via YUV sampling factor validation error

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image loading, resulting in a reliable denial-of-service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 5.3
nvd
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image loading, resulting in a reliable denial-of-service. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 5.3
debian
около 1 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

suse-cvrf
17 дней назад

Security update for GraphicsMagick

CVSS3: 5.3
github
около 1 месяца назад

ImageMagick has Division-by-Zero in YUV sampling factor validation, which leads to crash

5.3 Medium

CVSS3