Логотип exploitDog
bind:CVE-2025-57807
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-57807

Количество 11

Количество 11

ubuntu логотип

CVE-2025-57807

2 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.

CVSS3: 3.8
EPSS: Низкий
redhat логотип

CVE-2025-57807

2 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2025-57807

2 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.

CVSS3: 3.8
EPSS: Низкий
debian логотип

CVE-2025-57807

2 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 3.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03616-1

20 дней назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03510-1

27 дней назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03509-1

27 дней назад

Security update for ImageMagick

EPSS: Низкий
github логотип

GHSA-23hg-53q6-hqfg

2 месяца назад

ImageMagick BlobStream Forward-Seek Under-Allocation

CVSS3: 3.8
EPSS: Низкий
fstec логотип

BDU:2025-12702

2 месяца назад

Уязвимость функций SeekBlob() и WriteBlob() консольного графического редактора ImageMagick, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20251030-08

6 дней назад

Уязвимость ImageMagick

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20251030-07

6 дней назад

Уязвимость ImageMagick7

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-57807

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.

CVSS3: 3.8
0%
Низкий
2 месяца назад
redhat логотип
CVE-2025-57807

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.

CVSS3: 4.2
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-57807

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.

CVSS3: 3.8
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-57807

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 3.8
0%
Низкий
2 месяца назад
suse-cvrf логотип
SUSE-SU-2025:03616-1

Security update for ImageMagick

0%
Низкий
20 дней назад
suse-cvrf логотип
SUSE-SU-2025:03510-1

Security update for ImageMagick

0%
Низкий
27 дней назад
suse-cvrf логотип
SUSE-SU-2025:03509-1

Security update for ImageMagick

0%
Низкий
27 дней назад
github логотип
GHSA-23hg-53q6-hqfg

ImageMagick BlobStream Forward-Seek Under-Allocation

CVSS3: 3.8
0%
Низкий
2 месяца назад
fstec логотип
BDU:2025-12702

Уязвимость функций SeekBlob() и WriteBlob() консольного графического редактора ImageMagick, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20251030-08

Уязвимость ImageMagick

CVSS3: 9.8
0%
Низкий
6 дней назад
redos логотип
ROS-20251030-07

Уязвимость ImageMagick7

CVSS3: 9.8
0%
Низкий
6 дней назад

Уязвимостей на страницу