Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-25989

Опубликовано: 24 фев. 2026
Источник: redhat
CVSS3: 7.5

Описание

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file can cause a denial of service. An off-by-one boundary check (> instead of >=) that allows bypass the guard and reach an undefined (size_t) cast. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

A flaw was found in ImageMagick, a software used for editing and manipulating digital images. A remote attacker could exploit an off-by-one boundary check vulnerability by providing a specially crafted SVG (Scalable Vector Graphics) file. This could lead to a denial of service (DoS) condition, making the software unavailable to legitimate users.

Отчет

This is a MODERATE impact flaw in ImageMagick that could lead to a denial of service when processing a specially crafted SVG file. Red Hat Enterprise Linux 6 ELS and 7 ELS, as well as Community Projects like Fedora and EPEL, include ImageMagick. Exploitation requires an attacker to provide a malicious SVG file to a system utilizing ImageMagick for image processing.

Меры по смягчению последствий

To mitigate this issue, avoid processing untrusted SVG files with ImageMagick. If ImageMagick is used in an automated or server-side context, consider implementing sandboxing mechanisms or restricting the input sources to trusted origins to limit exposure to specially crafted SVG files.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickOut of support scope
Red Hat Enterprise Linux 7ImageMagickOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-193
https://bugzilla.redhat.com/show_bug.cgi?id=2442136ImageMagick: ImageMagick: Denial of Service via crafted SVG file

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file can cause a denial of service. An off-by-one boundary check (`>` instead of `>=`) that allows bypass the guard and reach an undefined `(size_t)` cast. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 7.5
nvd
около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a crafted SVG file can cause a denial of service. An off-by-one boundary check (`>` instead of `>=`) that allows bypass the guard and reach an undefined `(size_t)` cast. Versions 7.1.2-15 and 6.9.13-40 contain a patch.

CVSS3: 7.5
debian
около 1 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 7.5
github
около 1 месяца назад

ImageMagick: Integer overflow or wraparound and incorrect conversion between numeric types in the internal SVG decoder

suse-cvrf
19 дней назад

Security update for ImageMagick

7.5 High

CVSS3