Opened 8 months ago

Closed 8 months ago

#22802 closed enhancement (fixed)

ImageMagick-7.1.2-13

Reported by: Douglas R. Reno Owned by: Douglas R. Reno
Priority: high Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New patch version for BLFS 13.0.

Change History (5)

comment:1 by Douglas R. Reno, 8 months ago

Milestone: 13.1 → 13.0

comment:2 by Douglas R. Reno, 8 months ago

Owner: changed from blfs-book to Douglas R. Reno
Status: new → assigned

comment:3 by Douglas R. Reno, 8 months ago

Priority: normal → high

There are numerous changes here because we are 12 versions behind, please see ​https://github.com/ImageMagick/Website/blob/main/ChangeLog.md

That being said though, there are numerous security issues here as well, many of which have proof of concepts for shell access in the case of RCEs. Note that for 99% of our users though, the RCE vulnerabilities are really just arbitrary code execution vulnerabilities that can happen if they load a malicious file.

Integer Overflow in BMP Decoder (ReadBMP). Possible RCE though. 4.4 Medium, and only exploitable on 32-bit architectures. CVE-2025-62171

CLAHE : Unsigned underflow and division-by-zero lead to OOB pointer arithmetic and process crash (DoS). 4.7 Medium. CVE-2025-62594

Converting a malicious MVG file to SVG caused an integer overflow. Rated as 5.3 Moderate. Just an application crash though. CVE-2025-69204.

Magick's failure to limit MVG mutual references forming a loop. Denial of service due to a stack overflow. Rated as 4.0 Moderate. CVE-2025-68950

Magick's failure to limit the depth of SVG file reads caused a DoS attack. Stack overflow, denial of service. Rated as 5.3 Moderate. CVE-2025-68618.

Heap buffer overflow with attacker-controlled data in XBM parser. Rated as 8.1 High. RCE. CVE-2026-23876

NULL pointer dereference in MSL parser via <comment> tag before image load. Rated as 6.5 Moderate. DoS. CVE-2026-23952.

comment:4 by Douglas R. Reno, 8 months ago

While collecting data for the security advisory, I've discovered that some vulnerabilities have been updated to Critical.

comment:5 by Douglas R. Reno, 8 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at 207e0e02e73cc913c35418cf2507fdcc3497b2fd

SA-12.4-094 issued.

Note: See TracTickets for help on using tickets.