PT-2025-44038 · Unknown+3 · Imagemagick+3

Published

2025-10-27

·

Updated

2026-01-29

·

CVE-2025-62594

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions ImageMagick versions prior to 7.1.2-8
Description ImageMagick contains flaws within the CLAHEImage function related to unsigned integer underflow and division-by-zero. When the tile width or height is zero, an unsigned underflow occurs during pointer arithmetic, potentially leading to out-of-bounds memory access. Additionally, division-by-zero can cause immediate crashes. These issues can be triggered by specifying exact tiles with a value of zero (e.g., using the CLI option clahe 0x0!) or through automatic tile derivation with very small images. The primary impact is denial-of-service, resulting in crashes or resource exhaustion. While memory corruption is possible, reliable code execution has not been demonstrated. The vulnerable code is located in MagickCore/enhance.c around lines 609 and 669. The issue can be triggered via the command line interface or API.
Recommendations Update ImageMagick to version 7.1.2-8 or later.

Exploit

Fix

DoS

Buffer Overflow

Integer Underflow

Divide By Zero

Weakness Enumeration

Related Identifiers

BDU:2026-03385
CVE-2025-62594
GHSA-WPP4-VQFQ-V4HP
OESA-2025-2587
OESA-2025-2588
OESA-2025-2589
OESA-2025-2590
OESA-2025-2631
OPENSUSE-SU-2025:15685-1
OPENSUSE-SU-2025:20162-1
SUSE-SU-2025:21211-1
SUSE-SU-2025:3956-1
SUSE-SU-2025:3978-1
SUSE-SU-2025:3985-1
SUSE-SU-2025_3956-1
SUSE-SU-2025_3978-1
SUSE-SU-2025_3985-1

Affected Products

Debian
Imagemagick
Red Os
Suse