ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.
History

Fri, 15 Aug 2025 19:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*

Thu, 14 Aug 2025 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Imagemagick
Imagemagick imagemagick
Vendors & Products Imagemagick
Imagemagick imagemagick
References
Metrics threat_severity

None

threat_severity

Important


Wed, 13 Aug 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 13 Aug 2025 14:15:00 +0000

Type Values Removed Values Added
Description ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.
Title ImageMagick: heap-buffer overflow read in MNG magnification with alpha
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-08-13T13:59:23.354Z

Updated: 2025-08-13T14:35:59.815Z

Reserved: 2025-08-04T17:34:24.421Z

Link: CVE-2025-55004

cve-icon Vulnrichment

Updated: 2025-08-13T14:35:45.062Z

cve-icon NVD

Status : Analyzed

Published: 2025-08-13T14:15:32.733

Modified: 2025-08-15T19:31:52.070

Link: CVE-2025-55004

cve-icon Redhat

Severity : Important

Publid Date: 2025-08-13T13:59:23Z

Links: CVE-2025-55004 - Bugzilla