发布时间: 2025年7月26日
修改时间: 2025年7月26日
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick mogrify` command, specifying multiple consecutive `%d` format specifiers in a filename template causes internal pointer arithmetic to generate an address below the beginning of the stack buffer, resulting in a stack overflow through `vsnprintf()`. Versions 7.1.2-0 and 6.9.13-26 fix the issue.
NVD | openEuler | |
---|---|---|
Confidentiality | High | None |
Attack Vector | Network | Network |
CVSS评分 | 9.8 | 7.4 |
Attack Complexity | Low | High |
Privileges Required | None | None |
Scope | Unchanged | Unchanged |
Integrity | High | High |
User Interaction | None | None |
Availability | High | High |
公告名 | 概要 | 发布时间 |
---|---|---|
KylinSec-SA-2025-2753 | ImageMagick security update | 2025年8月12日 |
产品 | 包 | 状态 |
---|---|---|
KY3.4-5 | ImageMagick | Fixed |
V6 | ImageMagick | Fixed |
KY3.5.3 | ImageMagick | Fixed |
KY3.5.2 | ImageMagick | Fixed |