Name | CVE-2025-55004 |
Description | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1. |
Source | CVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Debian Bugs | 1111101 |
Vulnerable and fixed packages
The table below lists information on source packages.
Source Package | Release | Version | Status |
---|
imagemagick (PTS) | bullseye | 8:6.9.11.60+dfsg-1.3+deb11u4 | fixed |
| bullseye (security) | 8:6.9.11.60+dfsg-1.3+deb11u5 | fixed |
| bookworm | 8:6.9.11.60+dfsg-1.6+deb12u3 | fixed |
| bookworm (security) | 8:6.9.11.60+dfsg-1.6+deb12u1 | fixed |
| trixie | 8:7.1.1.43+dfsg1-1 | vulnerable |
| forky | 8:7.1.1.43+dfsg1-1+deb13u1 | vulnerable |
| sid | 8:7.1.2.1+dfsg1-1 | fixed |
The information below is based on the following data on fixed versions.
Notes
[bookworm] - imagemagick <not-affected> (Vulnerable code not present, specific to IM7)
[bullseye] - imagemagick <not-affected> (Vulnerable code not present, specific to IM7)
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-cjc8-g9w8-chfw
https://github.com/ImageMagick/ImageMagick/commit/55d97055e00a7bc7ae2776c99824002fbb4a72aa (7.1.2-1)