• CVE-2025-55212

发布时间: 2025年9月5日

修改时间: 2025年9月12日

概要

A vulnerability classified as problematic was found in ImageMagick up to 6.9.13-27/7.1.2-1 (Image Processing Software).The manipulation of the argument width/height with an unknown input leads to a unknown weakness. The CWE definition for the vulnerability is CWE-369. The product divides a value by zero.As an impact it is known to affect availability.Upgrading to version 6.9.13-28 or 7.1.2-2 eliminates this vulnerability. The upgrade is hosted for download at github.com. Applying the patch 5f0bcf986b8b5e90567750d31a37af502b73f2af is able to eliminate this problem. The bugfix is ready for download at github.com. The best possible mitigation is suggested to be upgrading to the latest version.

CVSS v3 指标

NVD openEuler
Confidentiality None None
Attack Vector Network Network
CVSS评分 7.5 3.7
Attack Complexity Low High
Privileges Required None None
Scope Unchanged Unchanged
Integrity None None
User Interaction None None
Availability High Low

安全公告

公告名 概要 发布时间
KylinSec-SA-2025-2853 ImageMagick security update 2025年9月24日
KylinSec-SA-2025-2871 ImageMagick security update 2025年9月15日
KylinSec-SA-2025-2895 ImageMagick security update 2025年9月18日

影响产品

产品 状态
KY3.4-5A ImageMagick Fixed
V6 ImageMagick Fixed
KY3.5.3 ImageMagick Fixed
KY3.5.2 ImageMagick Fixed