CVE-2025-55004

HIGH

ImageMagick <7.1.2-1 - Memory Corruption

Title source: llm
STIX 2.1

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.

References (2)

Core 2
Core References
Issue Tracking x_refsource_misc
https://goo.gle/bigsleep

Scores

CVSS v3 7.6
EPSS 0.0007
EPSS Percentile 20.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-122
Status published
Products (19)
imagemagick/imagemagick < 7.1.2-1
nuget/Magick.NET-Q16-AnyCPU 0 - 14.8.0NuGet
nuget/Magick.NET-Q16-arm64 0 - 14.8.0NuGet
nuget/Magick.NET-Q16-HDRI-AnyCPU 0 - 14.8.0NuGet
nuget/Magick.NET-Q16-HDRI-arm64 0 - 14.8.0NuGet
nuget/Magick.NET-Q16-HDRI-OpenMP-arm64 0 - 14.8.0NuGet
nuget/Magick.NET-Q16-HDRI-OpenMP-x64 0 - 14.8.0NuGet
nuget/Magick.NET-Q16-HDRI-x64 0 - 14.8.0NuGet
nuget/Magick.NET-Q16-HDRI-x86 0 - 14.8.0NuGet
nuget/Magick.NET-Q16-OpenMP-arm64 0 - 14.8.0NuGet
... and 9 more
Published Aug 13, 2025
Tracked Since Feb 18, 2026