Heap-based Buffer Over-read in GraphicsMagick Product by GraphicsMagick
CVE-2025-32460

4MEDIUM

Key Information:

Vendor
CVE Published:
9 April 2025

What is CVE-2025-32460?

The vulnerability in GraphicsMagick prior to the specified commit introduces a heap-based buffer over-read during the processing of JXL images. This issue arises in the ReadJXLImage function within coders/jxl.c, specifically linked to the ImportViewPixelArea call. This can lead to potential data exposure or other unintended consequences, emphasizing the importance of patching to the latest version to maintain security.

Affected Version(s)

GraphicsMagick 0 < 8e56520435df50f618a03f2721a39a70a515f1cb

References

CVSS V3.1

Score:
4
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.