Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-25968

Опубликовано: 24 фев. 2026
Источник: redhat
CVSS3: 7.4
EPSS Низкий

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a fixed-size stack buffer, leading to memory corruption. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

A flaw was found in ImageMagick. A remote attacker could exploit a stack buffer overflow vulnerability by providing a specially crafted image file with a long attribute value. This flaw occurs when processing an attribute in msl.c, leading to memory corruption. This can result in unpredictable behavior or a denial of service.

Отчет

A MODERATE impact stack buffer overflow flaw exists in ImageMagick. This vulnerability occurs when processing a specially crafted image file containing a long attribute value, leading to memory corruption, unpredictable behavior, or a denial of service. This affects ImageMagick as shipped in Red Hat Enterprise Linux, Fedora, and Community Projects, requiring the processing of a malicious image file for exploitation.

Меры по смягчению последствий

To reduce the risk associated with this vulnerability, avoid processing untrusted or maliciously crafted image files with ImageMagick. If ImageMagick is not required for system operations, consider removing packages that depend on it. Removing ImageMagick or its dependent packages may affect applications that rely on its image processing capabilities.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2442125ImageMagick: ImageMagick: Memory corruption via stack buffer overflow when processing an attribute

EPSS

Процентиль: 18%
0.00056
Низкий

7.4 High

CVSS3

Связанные уязвимости

CVSS3: 7.4
ubuntu
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a fixed-size stack buffer, leading to memory corruption. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 7.4
nvd
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a stack buffer overflow occurs when processing the an attribute in msl.c. A long value overflows a fixed-size stack buffer, leading to memory corruption. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 7.4
debian
около 1 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 7.4
github
16 дней назад

ImageMagick: MSL attribute stack buffer overflow leads to out of bounds write.

suse-cvrf
19 дней назад

Security update for ImageMagick

EPSS

Процентиль: 18%
0.00056
Низкий

7.4 High

CVSS3