Heap Buffer Overflow in ImageMagick Affects Various Versions
CVE-2025-53014
3.7LOW
What is CVE-2025-53014?
A heap buffer overflow vulnerability exists in ImageMagick, free and open-source software utilized for image editing. This issue arises from an off-by-one error in the 'InterpretImageFilename' function, leading to out-of-bounds memory access when processing format strings with consecutive percent signs ('%%'). Users should upgrade to versions 7.1.2-0 or 6.9.13-26 to mitigate this vulnerability.
Affected Version(s)
ImageMagick < 7.1.2-0 < 7.1.2-0
ImageMagick < 6.9.13-26 < 6.9.13-26
References
CVSS V3.1
Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved