CVE-2025-55005 Details
Description
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, when preparing to transform from Log to sRGB colorspaces, the logmap construction fails to handle cases where the reference-black or reference-white value is larger than 1024. This leads to corrupting memory beyond the end of the allocated logmap buffer. This issue has been patched in version 7.1.2-1.
A heap-buffer overflow vulnerability has been identified in ImageMagick versions prior to 7.1.2-1. The issue arises in the logmap construction process when converting from Log to sRGB colorspaces. Specifically, the vulnerability occurs if the reference-black or reference-white values exceed 1024, leading to memory corruption beyond the allocated logmap buffer. This vulnerability can be exploited by creating a MIFF file with a large reference-black value, which triggers the overflow when the file is processed.
Users should upgrade to ImageMagick version 7.1.2-1 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v393-38qx-v8fp | CISA-ADP | ExploitThird Party Advisory |
| https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v393-38qx-v8fp | [email protected] | ExploitThird Party Advisory |
| https://goo.gle/bigsleep | [email protected] | Issue Tracking |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| imagemagick imagemagick | < 7.1.2-1 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Aug 15, 2025 | Initial Analysis | [email protected] |
| Aug 13, 2025 | CVE Modified | CISA-ADP |
| Aug 13, 2025 | New CVE Received | [email protected] |