CVE-2025-57807
05.09.2025, 22:15
ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2 arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.Enginsight
Vendor | Product | Version |
---|---|---|
imagemagick | imagemagick | 𝑥 < 6.9.13-29 |
imagemagick | imagemagick | 7.0.0-0 ≤ 𝑥 < 7.1.2-3 |
𝑥
= Vulnerable software versions

Debian Releases
Vulnerability Media Exposure