PT-2025-42625 · Unknown+5 · Imagemagick+5

Published

2025-10-17

·

Updated

2026-01-06

·

CVE-2025-62171

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-7 and 6.9.13-32
Description ImageMagick is a software suite for displaying, converting, and editing raster image files. An integer overflow exists in the BMP decoder on 32-bit systems in versions prior to 7.1.2-7 and 6.9.13-32. The issue occurs in coders/bmp.c when calculating the extent value by multiplying image columns by bits per pixel. A malicious BMP file with specific dimensions can cause this multiplication to overflow and wrap to zero. The overflow check is ineffective as it is placed after the overflow occurs. A crafted 58-byte BMP file with a width of 536,870,912 and 32 bits per pixel can trigger the overflow, resulting in a zero bytes per line calculation. This affects 32-bit builds of ImageMagick where resource limits for width, height, and area have been manually increased beyond their defaults. 64-bit systems and systems using default resource limits are not vulnerable.
Recommendations Update to ImageMagick version 7.1.2-7 or later. Update to ImageMagick version 6.9.13-32 or later.

Exploit

Fix

DoS

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2025-16112
CVE-2025-62171
DLA-4339-1
ECHO-8C44-9B92-AAE4
GHSA-9PP9-CFWX-54RM
OESA-2025-2497
OESA-2025-2498
OESA-2025-2499
OESA-2025-2500
OESA-2025-2501
OESA-2025-2588
OPENSUSE-SU-2025:15650-1
OPENSUSE-SU-2025:20162-1
RHSA-2026:3058
SUSE-SU-2025:21211-1
SUSE-SU-2025:3796-1
SUSE-SU-2025:3844-1
SUSE-SU-2025:3867-1
SUSE-SU-2025:3918-1
SUSE-SU-2025_3796-1
SUSE-SU-2025_3844-1
SUSE-SU-2025_3867-1
SUSE-SU-2025_3918-1
USN-7876-1

Affected Products

Debian
Imagemagick
Linuxmint
Red Os
Suse
Ubuntu