CVE-2025-53101
14.07.2025, 20:15
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal pointer arithmetic to generate an address below the beginning of the stack buffer, resulting in a stack overflow through `vsnprintf()`. Versions 7.1.2-0 and 6.9.13-26 fix the issue.
Vendor | Product | Version |
---|---|---|
imagemagick | imagemagick | 𝑥 < 6.9.13-26 |
imagemagick | imagemagick | 7.0.0-0 ≤ 𝑥 < 7.1.2-0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
imagemagick |
|
Common Weakness Enumeration