ECHO-8c44-9b92-aae4

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-8c44-9b92-aae4.json
JSON Data
https://api.test.osv.dev/v1/vulns/ECHO-8c44-9b92-aae4
Upstream
Withdrawn
2025-10-28T08:30:08Z
Published
2026-01-28T01:02:42Z
Modified
2026-09-15T00:47:43Z
Summary
Possible integer overflow issue in the BMP decoder. Will only affect 32-bit builds so not applicable. There is a fix that doesn't apply cleanly to our build because there is another patch to apply before it. Again it's irrelevant because the issue will only affect 32-bit builds. https://security-tracker.debian.org/tracker/CVE-2025-62171 https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9pp9-cfwx-54rm https://github.com/ImageMagick/ImageMagick/commit/cea1693e2ded51b4cc91c70c54096cbed1691c00
Details
References

Affected packages

Echo / imagemagick

Package

Name
imagemagick
Purl
pkg:deb/echo/imagemagick

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8:7.1.1.43+dfsg1-1+deb13u2

Database specific

source
"https://advisory.echohq.com/osv/ECHO-8c44-9b92-aae4.json"