Image Depth Mishandling in ImageMagick Affects Multiple Versions
CVE-2025-43965

2.9LOW

Key Information:

Vendor
CVE Published:
23 April 2025

What is CVE-2025-43965?

In the MIFF image processing module of ImageMagick, a flaw exists that mishandles image depth following the use of the SetQuantumFormat function. This vulnerability affects the proper rendering and manipulation of images, potentially leading to unintended consequences in image processing tasks. Users are advised to update to the latest version to mitigate risks associated with this issue.

Affected Version(s)

ImageMagick 0 < 7.1.1-44

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.