Логотип exploitDog
bind: "CVE-2025-65955"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2025-65955"

Количество 10

Количество 10

ubuntu логотип

CVE-2025-65955

около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo->font, freeing the font string but leaving _drawInfo->font pointing to freed memory while _drawInfo->family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo->font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo->font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.

CVSS3: 4.9
EPSS: Низкий
nvd логотип

CVE-2025-65955

около 1 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo->font, freeing the font string but leaving _drawInfo->font pointing to freed memory while _drawInfo->family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo->font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo->font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.

CVSS3: 4.9
EPSS: Низкий
debian логотип

CVE-2025-65955

около 1 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 4.9
EPSS: Низкий
redos логотип

ROS-20251223-7302

24 дня назад

Уязвимость ImageMagick7

CVSS3: 6.1
EPSS: Низкий
redos логотип

ROS-20251223-7301

24 дня назад

Уязвимость ImageMagick

CVSS3: 6.1
EPSS: Низкий
github логотип

GHSA-q3hc-j9x5-mp9m

около 1 месяца назад

Withdrawn Advisory: ImageMagick has a use-after-free/double-free risk in Options::fontFamily when clearing family

CVSS3: 4.9
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0011-1

11 дней назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4428-1

30 дней назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:4427-1

30 дней назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0013-1

11 дней назад

Security update for ImageMagick

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-65955

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo->font, freeing the font string but leaving _drawInfo->font pointing to freed memory while _drawInfo->family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo->font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo->font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.

CVSS3: 4.9
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2025-65955

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo->font, freeing the font string but leaving _drawInfo->font pointing to freed memory while _drawInfo->family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo->font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo->font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.

CVSS3: 4.9
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-65955

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 4.9
0%
Низкий
около 1 месяца назад
redos логотип
ROS-20251223-7302

Уязвимость ImageMagick7

CVSS3: 6.1
0%
Низкий
24 дня назад
redos логотип
ROS-20251223-7301

Уязвимость ImageMagick

CVSS3: 6.1
0%
Низкий
24 дня назад
github логотип
GHSA-q3hc-j9x5-mp9m

Withdrawn Advisory: ImageMagick has a use-after-free/double-free risk in Options::fontFamily when clearing family

CVSS3: 4.9
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0011-1

Security update for ImageMagick

11 дней назад
suse-cvrf логотип
SUSE-SU-2025:4428-1

Security update for ImageMagick

30 дней назад
suse-cvrf логотип
SUSE-SU-2025:4427-1

Security update for ImageMagick

30 дней назад
suse-cvrf логотип
SUSE-SU-2026:0013-1

Security update for ImageMagick

11 дней назад

Уязвимостей на страницу