Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-25898

Опубликовано: 24 фев. 2026
Источник: redhat
CVSS3: 6.5

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by GetPixelIndex() before using it as an array subscript. In HDRI builds, Quantum is a floating-point type, so pixel index values can be negative. An attacker can craft an image with negative pixel index values to trigger a global buffer overflow read during conversion, leading to information disclosure or a process crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

A flaw was found in ImageMagick. A remote attacker can exploit this vulnerability by crafting a malicious image file. The UIL and XPM image encoders do not properly validate pixel index values, which can become negative in High Dynamic Range Imaging (HDRI) builds. This improper validation leads to a global buffer overflow read, potentially resulting in information disclosure or a denial of service (DoS) due to a process crash.

Отчет

This MODERATE impact vulnerability in ImageMagick's UIL and XPM image encoders allows for a global buffer overflow read when processing specially crafted images with negative pixel index values. This flaw can lead to information disclosure or a denial of service. Red Hat Enterprise Linux and Community Projects that include ImageMagick are affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2442102ImageMagick: ImageMagick: Information disclosure or denial of service via crafted image with invalid pixel index

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by `GetPixelIndex()` before using it as an array subscript. In HDRI builds, `Quantum` is a floating-point type, so pixel index values can be negative. An attacker can craft an image with negative pixel index values to trigger a global buffer overflow read during conversion, leading to information disclosure or a process crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 6.5
nvd
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the UIL and XPM image encoder do not validate the pixel index value returned by `GetPixelIndex()` before using it as an array subscript. In HDRI builds, `Quantum` is a floating-point type, so pixel index values can be negative. An attacker can craft an image with negative pixel index values to trigger a global buffer overflow read during conversion, leading to information disclosure or a process crash. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 6.5
debian
около 1 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 6.5
github
около 1 месяца назад

ImageMagick has Global Buffer Overflow (OOB Read) via Negative Pixel Index in UIL and XPM Writer

suse-cvrf
19 дней назад

Security update for ImageMagick

6.5 Medium

CVSS3