CVE-2025-53014

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-53014
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-53014.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-53014
Aliases
  • GHSA-hm4x-r5hc-794f
Downstream
Related
Published
2025-07-14T18:15:23Z
Modified
2025-07-15T14:53:31.575105Z
Summary
[none]
Details

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the InterpretImageFilename function. The issue stems from an off-by-one error that causes out-of-bounds memory access when processing format strings containing consecutive percent signs (%%). Versions 7.1.2-0 and 6.9.13-26 fix the issue.

References

Affected packages

Debian:11 / imagemagick

Package

Name
imagemagick
Purl
pkg:deb/debian/imagemagick?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8:6.*

8:6.9.11.60+dfsg-1.3
8:6.9.11.60+dfsg-1.3+deb11u1
8:6.9.11.60+dfsg-1.3+deb11u2
8:6.9.11.60+dfsg-1.3+deb11u3
8:6.9.11.60+dfsg-1.3+deb11u4
8:6.9.11.60+dfsg-1.3+deb11u5
8:6.9.11.60+dfsg-1.4
8:6.9.11.60+dfsg-1.5
8:6.9.11.60+dfsg-1.6
8:6.9.12.20+dfsg1-1
8:6.9.12.20+dfsg1-1.1
8:6.9.12.20+dfsg1-1.2
8:6.9.12.98+dfsg1-1
8:6.9.12.98+dfsg1-2
8:6.9.12.98+dfsg1-3
8:6.9.12.98+dfsg1-4
8:6.9.12.98+dfsg1-5
8:6.9.12.98+dfsg1-5.1~exp1
8:6.9.12.98+dfsg1-5.1
8:6.9.12.98+dfsg1-5.2
8:6.9.13.12+dfsg1-1

8:7.*

8:7.1.1.33+dfsg1-1
8:7.1.1.33+dfsg1-2
8:7.1.1.39+dfsg1-1
8:7.1.1.39+dfsg1-2
8:7.1.1.39+dfsg1-3
8:7.1.1.43+dfsg1-1
8:7.1.1.46+dfsg1-1
8:7.1.1.47+dfsg1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:12 / imagemagick

Package

Name
imagemagick
Purl
pkg:deb/debian/imagemagick?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8:6.*

8:6.9.11.60+dfsg-1.6
8:6.9.11.60+dfsg-1.6+deb12u1
8:6.9.11.60+dfsg-1.6+deb12u2
8:6.9.11.60+dfsg-1.6+deb12u3
8:6.9.12.20+dfsg1-1
8:6.9.12.20+dfsg1-1.1
8:6.9.12.20+dfsg1-1.2
8:6.9.12.98+dfsg1-1
8:6.9.12.98+dfsg1-2
8:6.9.12.98+dfsg1-3
8:6.9.12.98+dfsg1-4
8:6.9.12.98+dfsg1-5
8:6.9.12.98+dfsg1-5.1~exp1
8:6.9.12.98+dfsg1-5.1
8:6.9.12.98+dfsg1-5.2
8:6.9.13.12+dfsg1-1

8:7.*

8:7.1.1.33+dfsg1-1
8:7.1.1.33+dfsg1-2
8:7.1.1.39+dfsg1-1
8:7.1.1.39+dfsg1-2
8:7.1.1.39+dfsg1-3
8:7.1.1.43+dfsg1-1
8:7.1.1.46+dfsg1-1
8:7.1.1.47+dfsg1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Debian:13 / imagemagick

Package

Name
imagemagick
Purl
pkg:deb/debian/imagemagick?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

8:6.*

8:6.9.11.60+dfsg-1.6
8:6.9.12.20+dfsg1-1
8:6.9.12.20+dfsg1-1.1
8:6.9.12.20+dfsg1-1.2
8:6.9.12.98+dfsg1-1
8:6.9.12.98+dfsg1-2
8:6.9.12.98+dfsg1-3
8:6.9.12.98+dfsg1-4
8:6.9.12.98+dfsg1-5
8:6.9.12.98+dfsg1-5.1~exp1
8:6.9.12.98+dfsg1-5.1
8:6.9.12.98+dfsg1-5.2
8:6.9.13.12+dfsg1-1

8:7.*

8:7.1.1.33+dfsg1-1
8:7.1.1.33+dfsg1-2
8:7.1.1.39+dfsg1-1
8:7.1.1.39+dfsg1-2
8:7.1.1.39+dfsg1-3
8:7.1.1.43+dfsg1-1
8:7.1.1.46+dfsg1-1
8:7.1.1.47+dfsg1-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}