Memory Corruption in ImageMagick Affects Digital Image Editing Software
CVE-2025-55005
5.5MEDIUM
What is CVE-2025-55005?
ImageMagick, a widely used open-source software for editing and manipulating digital images, has a vulnerability that causes memory corruption during a color space transformation. Specifically, when transitioning from Log to sRGB colorspaces, the software improperly handles scenarios where the reference-black or reference-white values exceed 1024. This flaw results in memory being corrupted beyond the limits of the allocated logmap buffer. Users are advised to update to version 7.1.2-1 or later to mitigate this issue.
Affected Version(s)
ImageMagick < 7.1.2-1
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved