Integer Overflow Vulnerability in ImageMagick BMP Encoder
CVE-2025-57803
What is CVE-2025-57803?
ImageMagick, a widely used open-source image editing suite, is affected by an integer overflow in the BMP encoder’s scanline-stride computation. This vulnerability, present in versions prior to 6.9.13-28 and 7.1.2-2, allows attackers to exploit a flaw that causes the bytes_per_line to collapse to a smaller value. Consequently, the first row of an image can write beyond its intended memory bounds, leading to potential heap corruption. This flaw compromises the integrity of memory operations during image manipulation, making it significant for users relying on ImageMagick for secure image processing.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ImageMagick < 7.1.2-2 < 7.1.2-2
ImageMagick < 6.9.13-28 < 6.9.13-28
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved