PT-2025-32998 · Unknown+6 · Imagemagick+6
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
ImageMagick versions prior to 6.9.13-27
ImageMagick versions prior to 7.1.2-1
Description:
ImageMagick is a free and open-source software suite for editing and manipulating digital images. A function-type-mismatch exists in the splay tree cloning callback, leading to undefined behavior. This results in a deterministic abort when using UBSan (Undefined Behavior Sanitizer) builds, but does not cause a crash in non-sanitized builds.
Recommendations:
Update ImageMagick to version 6.9.13-27 or later.
Update ImageMagick to version 7.1.2-1 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Debian
Imagemagick
Linuxmint
Red Os
Suse
Ubuntu