Arbitrary Order Image Rendering Vulnerability in ImageMagick
CVE-2025-46393

2.9LOW

Key Information:

Vendor
CVE Published:
23 April 2025

What is CVE-2025-46393?

In certain versions of ImageMagick, particularly prior to 7.1.1-44, a vulnerability related to the processing of multispectral MIFF images can lead to improper handling of packet sizes. This issue may allow an attacker to manipulate the rendering process of image channels in arbitrary order, potentially leading to unexpected behaviors or impacts on image integrity.

Affected Version(s)

ImageMagick 0 < 7.1.1-44

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.