CVE-2025-53014 Information

Description

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the InterpretImageFilename function. The issue stems from an off-by-one error that causes out-of-bounds memory access when processing format strings containing consecutive percent signs (%%). Versions 7.1.2-0 and 6.9.13-26 fix the issue.

Reference

https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hm4x-r5hc-794f

CNNVD-202507-1852 (Published: 2025-07-14)

Share on: