Логотип exploitDog
bind:"CVE-2025-57803"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2025-57803"

Количество 14

Количество 14

ubuntu логотип

CVE-2025-57803

2 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.

CVSS3: 7.5
EPSS: Низкий
redhat логотип

CVE-2025-57803

2 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-57803

2 месяца назад

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-57803

2 месяца назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 7.5
EPSS: Низкий
redos логотип

ROS-20250905-10

2 месяца назад

Уязвимость ImageMagick7

CVSS3: 8.8
EPSS: Низкий
redos логотип

ROS-20250905-09

2 месяца назад

Уязвимость ImageMagick

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-mxvv-97wh-cfmm

2 месяца назад

ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow

CVSS3: 7.5
EPSS: Низкий
oracle-oval логотип

ELSA-2025-16313

26 дней назад

ELSA-2025-16313: ImageMagick security update (IMPORTANT)

EPSS: Низкий
fstec логотип

BDU:2025-11265

3 месяца назад

Уязвимость функции bytes_per_line() компонента coders/bmp.c консольного графического редактора ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03150-1

около 2 месяцев назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03164-1

около 2 месяцев назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03152-1

около 2 месяцев назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03151-1

около 2 месяцев назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03113-1

около 2 месяцев назад

Security update for ImageMagick

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-57803

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.

CVSS3: 7.5
0%
Низкий
2 месяца назад
redhat логотип
CVE-2025-57803

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.

CVSS3: 7.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2025-57803

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.

CVSS3: 7.5
0%
Низкий
2 месяца назад
debian логотип
CVE-2025-57803

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 7.5
0%
Низкий
2 месяца назад
redos логотип
ROS-20250905-10

Уязвимость ImageMagick7

CVSS3: 8.8
0%
Низкий
2 месяца назад
redos логотип
ROS-20250905-09

Уязвимость ImageMagick

CVSS3: 8.8
0%
Низкий
2 месяца назад
github логотип
GHSA-mxvv-97wh-cfmm

ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow

CVSS3: 7.5
0%
Низкий
2 месяца назад
oracle-oval логотип
ELSA-2025-16313

ELSA-2025-16313: ImageMagick security update (IMPORTANT)

26 дней назад
fstec логотип
BDU:2025-11265

Уязвимость функции bytes_per_line() компонента coders/bmp.c консольного графического редактора ImageMagick, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 7.5
0%
Низкий
3 месяца назад
suse-cvrf логотип
SUSE-SU-2025:03150-1

Security update for ImageMagick

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03164-1

Security update for ImageMagick

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03152-1

Security update for ImageMagick

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03151-1

Security update for ImageMagick

около 2 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03113-1

Security update for ImageMagick

около 2 месяцев назад

Уязвимостей на страницу