Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 14

Количество 14

ubuntu логотип

CVE-2025-57807

около 1 года назад

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.

CVSS3: 3.8
EPSS: Низкий
redhat логотип

CVE-2025-57807

около 1 года назад

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.

CVSS3: 4.2
EPSS: Низкий
nvd логотип

CVE-2025-57807

около 1 года назад

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.

CVSS3: 3.8
EPSS: Низкий
debian логотип

CVE-2025-57807

около 1 года назад

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 3.8
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03616-1

12 месяцев назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03510-1

12 месяцев назад

Security update for ImageMagick

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2025:03509-1

12 месяцев назад

Security update for ImageMagick

EPSS: Низкий
github логотип

GHSA-23hg-53q6-hqfg

около 1 года назад

ImageMagick BlobStream Forward-Seek Under-Allocation

CVSS3: 3.8
EPSS: Низкий
fstec логотип

BDU:2025-12702

около 1 года назад

Уязвимость функций SeekBlob() и WriteBlob() консольного графического редактора ImageMagick, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20251030-08

11 месяцев назад

Уязвимость ImageMagick

CVSS3: 9.8
EPSS: Низкий
redos логотип

ROS-20251030-07

11 месяцев назад

Уязвимость ImageMagick7

CVSS3: 9.8
EPSS: Низкий
altlinux логотип

ALT-PU-2025-11737

около 1 года назад

ALT-PU-2025-11737: package `ImageMagick` update to version 7.1.2.3-alt1

CVSS3: 9.8
EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2025:20162-1

10 месяцев назад

Security update for ImageMagick

EPSS: Низкий
altlinux логотип

ALT-PU-2026-15577

4 дня назад

ALT-PU-2026-15577: package `ImageMagick` update to version 7.1.2.27-alt1

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2025-57807

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.

CVSS3: 3.8
0%
Низкий
около 1 года назад
redhat логотип
CVE-2025-57807

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.

CVSS3: 4.2
0%
Низкий
около 1 года назад
nvd логотип
CVE-2025-57807

ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.

CVSS3: 3.8
0%
Низкий
около 1 года назад
debian логотип
CVE-2025-57807

ImageMagick is free and open-source software used for editing and mani ...

CVSS3: 3.8
0%
Низкий
около 1 года назад
suse-cvrf логотип
SUSE-SU-2025:03616-1

Security update for ImageMagick

0%
Низкий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03510-1

Security update for ImageMagick

0%
Низкий
12 месяцев назад
suse-cvrf логотип
SUSE-SU-2025:03509-1

Security update for ImageMagick

0%
Низкий
12 месяцев назад
github логотип
GHSA-23hg-53q6-hqfg

ImageMagick BlobStream Forward-Seek Under-Allocation

CVSS3: 3.8
0%
Низкий
около 1 года назад
fstec логотип
BDU:2025-12702

Уязвимость функций SeekBlob() и WriteBlob() консольного графического редактора ImageMagick, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.8
0%
Низкий
около 1 года назад
redos логотип
ROS-20251030-08

Уязвимость ImageMagick

CVSS3: 9.8
0%
Низкий
11 месяцев назад
redos логотип
ROS-20251030-07

Уязвимость ImageMagick7

CVSS3: 9.8
0%
Низкий
11 месяцев назад
altlinux логотип
ALT-PU-2025-11737

ALT-PU-2025-11737: package `ImageMagick` update to version 7.1.2.3-alt1

CVSS3: 9.8
0%
Низкий
около 1 года назад
suse-cvrf логотип
openSUSE-SU-2025:20162-1

Security update for ImageMagick

10 месяцев назад
altlinux логотип
ALT-PU-2026-15577

ALT-PU-2026-15577: package `ImageMagick` update to version 7.1.2.27-alt1

CVSS3: 9.8
4 дня назад

Уязвимостей на страницу