ImageMagick: ImageMagick Integer Overflow leading to out of bounds read (32-bit only)
cve CVE-2025-66628 2 sources, 2 claims · Watch
Red Hat writes:
ImageMagick: ImageMagick Integer Overflow leading to out of bounds read (32-bit only) the claim
ImageMagick: ImageMagick Integer Overflow leading to out of bounds read (32-bit only) the claim
- Severity
- HIGH NVDimportant Red Hat
- CVSS
- 7.5 NVD7.5 Red Hat
- Vendor
- ImageMagick NVD
- Product
- ImageMagick NVD
- CWE
- CWE-125 NVDCWE-125 Red Hat
How far exploitation has got
- No public code known
- Proof of concept
- Proof of concept, verified
- A Metasploit module
- Exploited in the wild
- Used in ransomware campaigns
Timeline
| 2025-12-10 | first spoke of it: ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10. | NVD |
| 2025-12-10 | first spoke of it: ImageMagick: ImageMagick Integer Overflow leading to out of bounds read (32-bit only) | Red Hat |
What it is to other things
| affects | imagemagick/imagemagick NVD |
| made_by | imagemagick NVD |
Every value, with what each source said and its receipt
| Property | Source | Said | Means here | ||||
|---|---|---|---|---|---|---|---|
| Automatable automatable | NVD | yes An attacker can reliably run all of the kill chain's first four steps without a person. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "ImageMagick",
"vendor": "ImageMagick",
"versions": [
{
"status": "affected",
"version": "< 7.1.2-10"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"matchCriteriaId": "189F420B-9B0E-4AB1-9D20-3D7E5ACCBDEE",
"versionEndExcluding": "7.1.2-10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."
},
{
"lang": "es",
"value": "ImageMagick es una suite de software para crear, editar, componer o convertir imágenes de mapa de bits. En las versiones 7.1.2-9 y anteriores, el analizador de imágenes TIM (PSX TIM) contiene una vulnerabilidad crítica de desbordamiento de entero en su función ReadTIMImage (coders/tim.c). El código lee el ancho y el alto (valores de 16 bits) del encabezado del archivo y calcula image_size = 2 * width * height sin verificar si hay desbordamiento. En sistemas de 32 bits (o donde size_t es de 32 bits), este cálculo puede desbordarse si el ancho y el alto son grandes (por ejemplo, 65535), envolviéndose a un valor pequeño. Esto resulta en una pequeña asignación de memoria en el heap a través de AcquireQuantumMemory y operaciones posteriores que dependen de las dimensiones pueden desencadenar una lectura fuera de límites. Este problema se corrige en la versión 7.1.2-10."
}
],
"id": "CVE-2025-66628",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66628",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:38:44.136255Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:28.660",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8"
},
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS cvss | NVD | 7.5receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "ImageMagick",
"vendor": "ImageMagick",
"versions": [
{
"status": "affected",
"version": "< 7.1.2-10"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"matchCriteriaId": "189F420B-9B0E-4AB1-9D20-3D7E5ACCBDEE",
"versionEndExcluding": "7.1.2-10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."
},
{
"lang": "es",
"value": "ImageMagick es una suite de software para crear, editar, componer o convertir imágenes de mapa de bits. En las versiones 7.1.2-9 y anteriores, el analizador de imágenes TIM (PSX TIM) contiene una vulnerabilidad crítica de desbordamiento de entero en su función ReadTIMImage (coders/tim.c). El código lee el ancho y el alto (valores de 16 bits) del encabezado del archivo y calcula image_size = 2 * width * height sin verificar si hay desbordamiento. En sistemas de 32 bits (o donde size_t es de 32 bits), este cálculo puede desbordarse si el ancho y el alto son grandes (por ejemplo, 65535), envolviéndose a un valor pequeño. Esto resulta en una pequeña asignación de memoria en el heap a través de AcquireQuantumMemory y operaciones posteriores que dependen de las dimensiones pueden desencadenar una lectura fuera de límites. Este problema se corrige en la versión 7.1.2-10."
}
],
"id": "CVE-2025-66628",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66628",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:38:44.136255Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:28.660",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8"
},
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS cvss | Red Hat | 7.5receipt
What the source handed over{
"CVE": "CVE-2025-66628",
"CWE": "CWE-125",
"advisories": [],
"affected_packages": [],
"bugzilla": "2421159",
"bugzilla_description": "ImageMagick: ImageMagick Integer Overflow leading to out of bounds read (32-bit only)",
"cvss3_score": "7.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-12-10T22:04:49Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-66628.json",
"severity": "important"
} | — | ||||
| CVSS vector cvss_vector | NVD | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:Nreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "ImageMagick",
"vendor": "ImageMagick",
"versions": [
{
"status": "affected",
"version": "< 7.1.2-10"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"matchCriteriaId": "189F420B-9B0E-4AB1-9D20-3D7E5ACCBDEE",
"versionEndExcluding": "7.1.2-10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."
},
{
"lang": "es",
"value": "ImageMagick es una suite de software para crear, editar, componer o convertir imágenes de mapa de bits. En las versiones 7.1.2-9 y anteriores, el analizador de imágenes TIM (PSX TIM) contiene una vulnerabilidad crítica de desbordamiento de entero en su función ReadTIMImage (coders/tim.c). El código lee el ancho y el alto (valores de 16 bits) del encabezado del archivo y calcula image_size = 2 * width * height sin verificar si hay desbordamiento. En sistemas de 32 bits (o donde size_t es de 32 bits), este cálculo puede desbordarse si el ancho y el alto son grandes (por ejemplo, 65535), envolviéndose a un valor pequeño. Esto resulta en una pequeña asignación de memoria en el heap a través de AcquireQuantumMemory y operaciones posteriores que dependen de las dimensiones pueden desencadenar una lectura fuera de límites. Este problema se corrige en la versión 7.1.2-10."
}
],
"id": "CVE-2025-66628",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66628",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:38:44.136255Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:28.660",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8"
},
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CVSS vector cvss_vector | Red Hat | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:Nreceipt
What the source handed over{
"CVE": "CVE-2025-66628",
"CWE": "CWE-125",
"advisories": [],
"affected_packages": [],
"bugzilla": "2421159",
"bugzilla_description": "ImageMagick: ImageMagick Integer Overflow leading to out of bounds read (32-bit only)",
"cvss3_score": "7.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-12-10T22:04:49Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-66628.json",
"severity": "important"
} | — | ||||
| CWE cwe | NVD | CWE-125receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "ImageMagick",
"vendor": "ImageMagick",
"versions": [
{
"status": "affected",
"version": "< 7.1.2-10"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"matchCriteriaId": "189F420B-9B0E-4AB1-9D20-3D7E5ACCBDEE",
"versionEndExcluding": "7.1.2-10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."
},
{
"lang": "es",
"value": "ImageMagick es una suite de software para crear, editar, componer o convertir imágenes de mapa de bits. En las versiones 7.1.2-9 y anteriores, el analizador de imágenes TIM (PSX TIM) contiene una vulnerabilidad crítica de desbordamiento de entero en su función ReadTIMImage (coders/tim.c). El código lee el ancho y el alto (valores de 16 bits) del encabezado del archivo y calcula image_size = 2 * width * height sin verificar si hay desbordamiento. En sistemas de 32 bits (o donde size_t es de 32 bits), este cálculo puede desbordarse si el ancho y el alto son grandes (por ejemplo, 65535), envolviéndose a un valor pequeño. Esto resulta en una pequeña asignación de memoria en el heap a través de AcquireQuantumMemory y operaciones posteriores que dependen de las dimensiones pueden desencadenar una lectura fuera de límites. Este problema se corrige en la versión 7.1.2-10."
}
],
"id": "CVE-2025-66628",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66628",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:38:44.136255Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:28.660",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8"
},
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| CWE cwe | Red Hat | CWE-125receipt
What the source handed over{
"CVE": "CVE-2025-66628",
"CWE": "CWE-125",
"advisories": [],
"affected_packages": [],
"bugzilla": "2421159",
"bugzilla_description": "ImageMagick: ImageMagick Integer Overflow leading to out of bounds read (32-bit only)",
"cvss3_score": "7.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-12-10T22:04:49Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-66628.json",
"severity": "important"
} | — | ||||
| Exploitation exploitation | NVD | none No evidence of exploitation, and no public proof of concept. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "ImageMagick",
"vendor": "ImageMagick",
"versions": [
{
"status": "affected",
"version": "< 7.1.2-10"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"matchCriteriaId": "189F420B-9B0E-4AB1-9D20-3D7E5ACCBDEE",
"versionEndExcluding": "7.1.2-10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."
},
{
"lang": "es",
"value": "ImageMagick es una suite de software para crear, editar, componer o convertir imágenes de mapa de bits. En las versiones 7.1.2-9 y anteriores, el analizador de imágenes TIM (PSX TIM) contiene una vulnerabilidad crítica de desbordamiento de entero en su función ReadTIMImage (coders/tim.c). El código lee el ancho y el alto (valores de 16 bits) del encabezado del archivo y calcula image_size = 2 * width * height sin verificar si hay desbordamiento. En sistemas de 32 bits (o donde size_t es de 32 bits), este cálculo puede desbordarse si el ancho y el alto son grandes (por ejemplo, 65535), envolviéndose a un valor pequeño. Esto resulta en una pequeña asignación de memoria en el heap a través de AcquireQuantumMemory y operaciones posteriores que dependen de las dimensiones pueden desencadenar una lectura fuera de límites. Este problema se corrige en la versión 7.1.2-10."
}
],
"id": "CVE-2025-66628",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66628",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:38:44.136255Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:28.660",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8"
},
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Product product | NVD | ImageMagickreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "ImageMagick",
"vendor": "ImageMagick",
"versions": [
{
"status": "affected",
"version": "< 7.1.2-10"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"matchCriteriaId": "189F420B-9B0E-4AB1-9D20-3D7E5ACCBDEE",
"versionEndExcluding": "7.1.2-10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."
},
{
"lang": "es",
"value": "ImageMagick es una suite de software para crear, editar, componer o convertir imágenes de mapa de bits. En las versiones 7.1.2-9 y anteriores, el analizador de imágenes TIM (PSX TIM) contiene una vulnerabilidad crítica de desbordamiento de entero en su función ReadTIMImage (coders/tim.c). El código lee el ancho y el alto (valores de 16 bits) del encabezado del archivo y calcula image_size = 2 * width * height sin verificar si hay desbordamiento. En sistemas de 32 bits (o donde size_t es de 32 bits), este cálculo puede desbordarse si el ancho y el alto son grandes (por ejemplo, 65535), envolviéndose a un valor pequeño. Esto resulta en una pequeña asignación de memoria en el heap a través de AcquireQuantumMemory y operaciones posteriores que dependen de las dimensiones pueden desencadenar una lectura fuera de límites. Este problema se corrige en la versión 7.1.2-10."
}
],
"id": "CVE-2025-66628",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66628",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:38:44.136255Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:28.660",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8"
},
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Severity severity | NVD | HIGH From 7.0 to 8.9. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "ImageMagick",
"vendor": "ImageMagick",
"versions": [
{
"status": "affected",
"version": "< 7.1.2-10"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"matchCriteriaId": "189F420B-9B0E-4AB1-9D20-3D7E5ACCBDEE",
"versionEndExcluding": "7.1.2-10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."
},
{
"lang": "es",
"value": "ImageMagick es una suite de software para crear, editar, componer o convertir imágenes de mapa de bits. En las versiones 7.1.2-9 y anteriores, el analizador de imágenes TIM (PSX TIM) contiene una vulnerabilidad crítica de desbordamiento de entero en su función ReadTIMImage (coders/tim.c). El código lee el ancho y el alto (valores de 16 bits) del encabezado del archivo y calcula image_size = 2 * width * height sin verificar si hay desbordamiento. En sistemas de 32 bits (o donde size_t es de 32 bits), este cálculo puede desbordarse si el ancho y el alto son grandes (por ejemplo, 65535), envolviéndose a un valor pequeño. Esto resulta en una pequeña asignación de memoria en el heap a través de AcquireQuantumMemory y operaciones posteriores que dependen de las dimensiones pueden desencadenar una lectura fuera de límites. Este problema se corrige en la versión 7.1.2-10."
}
],
"id": "CVE-2025-66628",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66628",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:38:44.136255Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:28.660",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8"
},
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | high | ||||
| Severity severity | Red Hat | important A flaw that can easily compromise confidentiality, integrity or availability. receipt
What the source handed over{
"CVE": "CVE-2025-66628",
"CWE": "CWE-125",
"advisories": [],
"affected_packages": [],
"bugzilla": "2421159",
"bugzilla_description": "ImageMagick: ImageMagick Integer Overflow leading to out of bounds read (32-bit only)",
"cvss3_score": "7.5",
"cvss3_scoring_vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"cvss_score": null,
"cvss_scoring_vector": null,
"package_state": null,
"public_date": "2025-12-10T22:04:49Z",
"resource_url": "https://access.redhat.com/hydra/rest/securitydata/cve/CVE-2025-66628.json",
"severity": "important"
} | high | ||||
| Status status | NVD | Analyzedreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "ImageMagick",
"vendor": "ImageMagick",
"versions": [
{
"status": "affected",
"version": "< 7.1.2-10"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"matchCriteriaId": "189F420B-9B0E-4AB1-9D20-3D7E5ACCBDEE",
"versionEndExcluding": "7.1.2-10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."
},
{
"lang": "es",
"value": "ImageMagick es una suite de software para crear, editar, componer o convertir imágenes de mapa de bits. En las versiones 7.1.2-9 y anteriores, el analizador de imágenes TIM (PSX TIM) contiene una vulnerabilidad crítica de desbordamiento de entero en su función ReadTIMImage (coders/tim.c). El código lee el ancho y el alto (valores de 16 bits) del encabezado del archivo y calcula image_size = 2 * width * height sin verificar si hay desbordamiento. En sistemas de 32 bits (o donde size_t es de 32 bits), este cálculo puede desbordarse si el ancho y el alto son grandes (por ejemplo, 65535), envolviéndose a un valor pequeño. Esto resulta en una pequeña asignación de memoria en el heap a través de AcquireQuantumMemory y operaciones posteriores que dependen de las dimensiones pueden desencadenar una lectura fuera de límites. Este problema se corrige en la versión 7.1.2-10."
}
],
"id": "CVE-2025-66628",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66628",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:38:44.136255Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:28.660",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8"
},
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Technical impact technical_impact | NVD | partial The attacker gains limited control, or limited information. receipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "ImageMagick",
"vendor": "ImageMagick",
"versions": [
{
"status": "affected",
"version": "< 7.1.2-10"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"matchCriteriaId": "189F420B-9B0E-4AB1-9D20-3D7E5ACCBDEE",
"versionEndExcluding": "7.1.2-10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."
},
{
"lang": "es",
"value": "ImageMagick es una suite de software para crear, editar, componer o convertir imágenes de mapa de bits. En las versiones 7.1.2-9 y anteriores, el analizador de imágenes TIM (PSX TIM) contiene una vulnerabilidad crítica de desbordamiento de entero en su función ReadTIMImage (coders/tim.c). El código lee el ancho y el alto (valores de 16 bits) del encabezado del archivo y calcula image_size = 2 * width * height sin verificar si hay desbordamiento. En sistemas de 32 bits (o donde size_t es de 32 bits), este cálculo puede desbordarse si el ancho y el alto son grandes (por ejemplo, 65535), envolviéndose a un valor pequeño. Esto resulta en una pequeña asignación de memoria en el heap a través de AcquireQuantumMemory y operaciones posteriores que dependen de las dimensiones pueden desencadenar una lectura fuera de límites. Este problema se corrige en la versión 7.1.2-10."
}
],
"id": "CVE-2025-66628",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66628",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:38:44.136255Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:28.660",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8"
},
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — | ||||
| Vendor vendor | NVD | ImageMagickreceipt
What the source handed over{
"cve": {
"affected": [
{
"affectedData": [
{
"product": "ImageMagick",
"vendor": "ImageMagick",
"versions": [
{
"status": "affected",
"version": "< 7.1.2-10"
}
]
}
],
"source": "security-advisories@github.com"
}
],
"configurations": [
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:imagemagick:imagemagick:*:*:*:*:*:*:*:*",
"matchCriteriaId": "189F420B-9B0E-4AB1-9D20-3D7E5ACCBDEE",
"versionEndExcluding": "7.1.2-10",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
],
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bit values) from the file header and calculates image_size = 2 * width * height without checking for overflow. On 32-bit systems (or where size_t is 32-bit), this calculation can overflow if width and height are large (e.g., 65535), wrapping around to a small value. This results in a small heap allocation via AcquireQuantumMemory and later operations relying on the dimensions can trigger an out of bounds read. This issue is fixed in version 7.1.2-10."
},
{
"lang": "es",
"value": "ImageMagick es una suite de software para crear, editar, componer o convertir imágenes de mapa de bits. En las versiones 7.1.2-9 y anteriores, el analizador de imágenes TIM (PSX TIM) contiene una vulnerabilidad crítica de desbordamiento de entero en su función ReadTIMImage (coders/tim.c). El código lee el ancho y el alto (valores de 16 bits) del encabezado del archivo y calcula image_size = 2 * width * height sin verificar si hay desbordamiento. En sistemas de 32 bits (o donde size_t es de 32 bits), este cálculo puede desbordarse si el ancho y el alto son grandes (por ejemplo, 65535), envolviéndose a un valor pequeño. Esto resulta en una pequeña asignación de memoria en el heap a través de AcquireQuantumMemory y operaciones posteriores que dependen de las dimensiones pueden desencadenar una lectura fuera de límites. Este problema se corrige en la versión 7.1.2-10."
}
],
"id": "CVE-2025-66628",
"lastModified": "2026-09-25T23:10:00.463",
"metrics": {
"cvssMetricV31": [
{
"cvssData": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "NONE",
"baseScore": 7.5,
"baseSeverity": "HIGH",
"confidentialityImpact": "HIGH",
"integrityImpact": "NONE",
"privilegesRequired": "NONE",
"scope": "UNCHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"version": "3.1"
},
"exploitabilityScore": 3.9,
"impactScore": 3.6,
"source": "security-advisories@github.com",
"type": "Secondary"
}
],
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-66628",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2025-12-11T15:38:44.136255Z",
"version": "2.0.3"
}
}
]
},
"published": "2025-12-10T22:16:28.660",
"references": [
{
"source": "security-advisories@github.com",
"tags": [
"Vendor Advisory"
],
"url": "https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6hjr-v6g4-3fm8"
},
{
"source": "security-advisories@github.com",
"tags": [
"Patch"
],
"url": "https://github.com/dlemstra/Magick.NET/commit/2dfa08e15cfd11016a79615994787b14f9048b1c"
}
],
"sourceIdentifier": "security-advisories@github.com",
"vulnStatus": "Analyzed",
"weaknesses": [
{
"description": [
{
"lang": "en",
"value": "CWE-125"
}
],
"source": "security-advisories@github.com",
"type": "Secondary"
}
]
}
} | — |