CVE-2025-57807

Name
CVE-2025-57807
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. ImageMagick versions lower than 14.8.2 include insecure functions: SeekBlob(), which permits advancing the stream offset beyond the current end without increasing capacity, and WriteBlob(), which then expands by quantum + length (amortized) instead of offset + length, and copies to data + offset. When offset ≫ extent, the copy targets memory beyond the allocation, producing a deterministic heap write on 64-bit builds. No 2⁶⁴ arithmetic wrap, external delegates, or policy settings are required. This is fixed in version 14.8.2.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/ImageMagick/ImageMagick/commit/077a417a19a5ea8c85559b602754a5b928eef23e
CONFIRM https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-23hg-53q6-hqfg
af854a3a-2127-422b-91ae-364da2661108 https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html

Match rules

CPE URI Source package Min version Max version
imagemagick >= 0 < 14.8.2
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* imagemagick >= None < 6.9.13-29
cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:* imagemagick >= 7.0.0-0 < 7.1.2-3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
imagemagick edge-community 7.1.1.41-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.1.43-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.1.44-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.1.44-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.1.44-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.1.44-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.1.44-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.2.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.2.1-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.2.1-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.2.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick 3.22-community 7.1.1.41-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick 3.22-community 7.1.2.0-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.2.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.2.3-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick 3.22-community 7.1.2.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.2.3-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
imagemagick edge-community 7.1.2.3-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable