Medium severity5.5NVD Advisory· Published Dec 8, 2020· Updated Jun 17, 2026
CVE-2020-25663
CVE-2020-25663
Description
A call to ConformPixelInfo() in the SetImageAlphaChannel() routine of /MagickCore/channel.c caused a subsequent heap-use-after-free or heap-buffer-overflow READ when GetPixelRed() or GetPixelBlue() was called. This could occur if an attacker is able to submit a malicious image file to be processed by ImageMagick and could lead to denial of service. It likely would not lead to anything further because the memory is used as pixel data and not e.g. a function pointer. This flaw affects ImageMagick versions prior to 7.0.9-0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- ImageMagick/ImageMagickdescription
- Range: <7.0.9-0
- osv-coords4 versionspkg:apk/chainguard/imagemagick-6pkg:apk/chainguard/imagemagick-6-devpkg:apk/chainguard/imagemagick-6-docpkg:apk/chainguard/imagemagick-6-static
< 0+ 3 more
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: < 0
Patches
Vulnerability mechanics
References
3- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- github.com/ImageMagick/ImageMagick/issues/1723nvdExploitThird Party Advisory
- github.com/ImageMagick/ImageMagick/issues/1723nvdThird Party Advisory
News mentions
0No linked articles in our index yet.