ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and caused a DoS attack. Version 7.1.2-12 fixes the issue.
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69204.json",
"cwe_ids": [
"CWE-190"
],
"cna_assigner": "GitHub_M"
}[
{
"source": "https://github.com/imagemagick/imagemagick/commit/2c08c2311693759153c9aa99a6b2dcb5f985681e",
"target": {
"file": "coders/svg.c"
},
"deprecated": false,
"digest": {
"line_hashes": [
"250793905562053045935767298593531572329",
"279307549927228078416277676774996777561",
"97549468744645899208811646419327880888",
"211577157460716540213459188606354731346",
"240770726493300823499462845280043934575",
"259313269618502434351109294310347997198",
"47724938908593270053738825597793042846",
"238323397171100682272507185485018287018",
"60092501584519222505490945569409011220",
"318952689604258496855614669679988729089",
"277968104194361378400411244286850358937",
"114464945609469469489881143661597210042",
"304850524041252850983414955855670527584",
"236820773024229907383783522678180842680",
"201644642556773469874408793282454625459",
"176509290569917644525239631808307067301",
"19137773161721127010893533576916352346",
"234498703447553212136700852353883480971",
"68910449650360579989355240287069961065",
"284372914057543377515853805023963770720",
"293664405702884073279494374764209203580",
"319989914568065886973240491235763648764",
"20946993898738180663599907475128112409"
],
"threshold": 0.9
},
"signature_type": "Line",
"signature_version": "v1",
"id": "CVE-2025-69204-3d064d16"
},
{
"source": "https://github.com/imagemagick/imagemagick/commit/2c08c2311693759153c9aa99a6b2dcb5f985681e",
"target": {
"function": "SVGStartElement",
"file": "coders/svg.c"
},
"deprecated": false,
"digest": {
"length": 28990.0,
"function_hash": "268451551813155349324272264890586043373"
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2025-69204-8d443796"
},
{
"source": "https://github.com/imagemagick/imagemagick/commit/2c08c2311693759153c9aa99a6b2dcb5f985681e",
"target": {
"function": "WriteSVGImage",
"file": "coders/svg.c"
},
"deprecated": false,
"digest": {
"length": 26855.0,
"function_hash": "181784090966882731223276978409997923158"
},
"signature_type": "Function",
"signature_version": "v1",
"id": "CVE-2025-69204-e18c513d"
}
]
"2026-04-24T17:12:33Z"
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-69204.json"