rpm package
opensuse/ImageMagick&distro=openSUSE Leap 15.6
pkg:rpm/opensuse/ImageMagick&distro=openSUSE%20Leap%2015.6
Vulnerabilities (76)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-25799 | — | < 7.1.1.21-150600.3.42.2 | 7.1.1.21-150600.3.42.2 | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image | ||
| CVE-2026-25798 | — | < 7.1.1.21-150600.3.42.2 | 7.1.1.21-150600.3.42.2 | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a NULL pointer dereference in ClonePixelCacheRepository allows a remote attacker to crash any application linked against ImageMagick by supplyi | ||
| CVE-2026-25797 | — | < 7.1.1.21-150600.3.42.2 | 7.1.1.21-150600.3.42.2 | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the ps coders, responsible for writing PostScript files, fails to sanitize the input before writing it into the PostScript header. An attacker | ||
| CVE-2026-25796 | — | < 7.1.1.21-150600.3.42.2 | 7.1.1.21-150600.3.42.2 | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSTEGANOImage()` (`coders/stegano.c`), the `watermark` Image object is not freed on three early-return paths, resulting in a definite me | ||
| CVE-2026-25795 | — | < 7.1.1.21-150600.3.42.2 | 7.1.1.21-150600.3.42.2 | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSFWImage()` (`coders/sfw.c`), when temporary file creation fails, `read_info` is destroyed before its `filename` member is accessed, ca | ||
| CVE-2026-25638 | — | < 7.1.1.21-150600.3.42.2 | 7.1.1.21-150600.3.42.2 | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, memory leak exists in `coders/msl.c`. In the `WriteMSLImage` function of the `msl.c` file, resources are allocated. But the function returns ea | ||
| CVE-2026-25637 | — | < 7.1.1.21-150600.3.42.2 | 7.1.1.21-150600.3.42.2 | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak in the ASHLAR image writer allows an attacker to exhaust process memory by providing a crafted image that results in small objects that are allo | ||
| CVE-2026-25576 | — | < 7.1.1.21-150600.3.42.2 | 7.1.1.21-150600.3.42.2 | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in multiple raw image format handles. The vulnerability occurs when processing images with -extrac | ||
| CVE-2026-24485 | — | < 7.1.1.21-150600.3.42.2 | 7.1.1.21-150600.3.42.2 | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sy | ||
| CVE-2026-24484 | — | < 7.1.1.21-150600.3.42.2 | 7.1.1.21-150600.3.42.2 | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15 and 6.9.13-40 contain a patch. | ||
| CVE-2026-24481 | — | < 7.1.1.21-150600.3.42.2 | 7.1.1.21-150600.3.42.2 | Feb 24, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted | ||
| CVE-2026-23952 | — | < 7.1.1.21-150600.3.38.1 | 7.1.1.21-150600.3.38.1 | Jan 22, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing tags before images are loaded. This can | ||
| CVE-2026-23876 | — | < 7.1.1.21-150600.3.38.1 | 7.1.1.21-150600.3.38.1 | Jan 20, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated hea | ||
| CVE-2026-23874 | — | < 7.1.1.21-150600.3.38.1 | 7.1.1.21-150600.3.38.1 | Jan 20, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-13 have a stack overflow via infinite recursion in MSL (Magick Scripting Language) `` command when writing to MSL format. Version 7.1.2-13 fixes the issue | ||
| CVE-2026-22770 | — | < 7.1.1.21-150600.3.38.1 | 7.1.1.21-150600.3.38.1 | Jan 20, 2026 | ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in versions prior to 7.1.2-13, the last element in the set is not properly initializ | ||
| CVE-2025-69204 | — | < 7.1.1.21-150600.3.35.1 | 7.1.1.21-150600.3.35.1 | Dec 30, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and cau | ||
| CVE-2025-68950 | — | < 7.1.1.21-150600.3.35.1 | 7.1.1.21-150600.3.35.1 | Dec 30, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a stack overflow. This is a DoS vulnerability, and any situation that allows readin | ||
| CVE-2025-68618 | — | < 7.1.1.21-150600.3.35.1 | 7.1.1.21-150600.3.35.1 | Dec 30, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue. | ||
| CVE-2025-66628 | — | < 7.1.1.21-150600.3.32.1 | 7.1.1.21-150600.3.32.1 | Dec 10, 2025 | ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bi | ||
| CVE-2025-65955 | — | < 7.1.1.21-150600.3.32.1 | 7.1.1.21-150600.3.32.1 | Dec 2, 2025 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family |
- CVE-2026-25799Feb 24, 2026affected < 7.1.1.21-150600.3.42.2fixed 7.1.1.21-150600.3.42.2
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a logic error in YUV sampling factor validation allows an invalid sampling factor to bypass checks and trigger a division-by-zero during image
- CVE-2026-25798Feb 24, 2026affected < 7.1.1.21-150600.3.42.2fixed 7.1.1.21-150600.3.42.2
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a NULL pointer dereference in ClonePixelCacheRepository allows a remote attacker to crash any application linked against ImageMagick by supplyi
- CVE-2026-25797Feb 24, 2026affected < 7.1.1.21-150600.3.42.2fixed 7.1.1.21-150600.3.42.2
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the ps coders, responsible for writing PostScript files, fails to sanitize the input before writing it into the PostScript header. An attacker
- CVE-2026-25796Feb 24, 2026affected < 7.1.1.21-150600.3.42.2fixed 7.1.1.21-150600.3.42.2
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSTEGANOImage()` (`coders/stegano.c`), the `watermark` Image object is not freed on three early-return paths, resulting in a definite me
- CVE-2026-25795Feb 24, 2026affected < 7.1.1.21-150600.3.42.2fixed 7.1.1.21-150600.3.42.2
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, in `ReadSFWImage()` (`coders/sfw.c`), when temporary file creation fails, `read_info` is destroyed before its `filename` member is accessed, ca
- CVE-2026-25638Feb 24, 2026affected < 7.1.1.21-150600.3.42.2fixed 7.1.1.21-150600.3.42.2
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, memory leak exists in `coders/msl.c`. In the `WriteMSLImage` function of the `msl.c` file, resources are allocated. But the function returns ea
- CVE-2026-25637Feb 24, 2026affected < 7.1.1.21-150600.3.42.2fixed 7.1.1.21-150600.3.42.2
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-15, a memory leak in the ASHLAR image writer allows an attacker to exhaust process memory by providing a crafted image that results in small objects that are allo
- CVE-2026-25576Feb 24, 2026affected < 7.1.1.21-150600.3.42.2fixed 7.1.1.21-150600.3.42.2
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap buffer over-read vulnerability exists in multiple raw image format handles. The vulnerability occurs when processing images with -extrac
- CVE-2026-24485Feb 24, 2026affected < 7.1.1.21-150600.3.42.2fixed 7.1.1.21-150600.3.42.2
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, when a PCD file does not contain a valid Sync marker, the DecodeImage() function becomes trapped in an infinite loop while searching for the Sy
- CVE-2026-24484Feb 24, 2026affected < 7.1.1.21-150600.3.42.2fixed 7.1.1.21-150600.3.42.2
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, Magick fails to check for multi-layer nested mvg conversions to svg, leading to DoS. Versions 7.1.2-15 and 6.9.13-40 contain a patch.
- CVE-2026-24481Feb 24, 2026affected < 7.1.1.21-150600.3.42.2fixed 7.1.1.21-150600.3.42.2
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, a heap information disclosure vulnerability exists in ImageMagick's PSD (Adobe Photoshop) format handler. When processing a maliciously crafted
- CVE-2026-23952Jan 22, 2026affected < 7.1.1.21-150600.3.38.1fixed 7.1.1.21-150600.3.38.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions 14.10.1 and below have a NULL pointer dereference vulnerability in the MSL (Magick Scripting Language) parser when processing tags before images are loaded. This can
- CVE-2026-23876Jan 20, 2026affected < 7.1.1.21-150600.3.38.1fixed 7.1.1.21-150600.3.38.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-13 and 6.9.13-38, a heap buffer overflow vulnerability in the XBM image decoder (ReadXBMImage) allows an attacker to write controlled data past the allocated hea
- CVE-2026-23874Jan 20, 2026affected < 7.1.1.21-150600.3.38.1fixed 7.1.1.21-150600.3.38.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-13 have a stack overflow via infinite recursion in MSL (Magick Scripting Language) `` command when writing to MSL format. Version 7.1.2-13 fixes the issue
- CVE-2026-22770Jan 20, 2026affected < 7.1.1.21-150600.3.38.1fixed 7.1.1.21-150600.3.38.1
ImageMagick is free and open-source software used for editing and manipulating digital images. The BilateralBlurImage method will allocate a set of double buffers inside AcquireBilateralTLS. But, in versions prior to 7.1.2-13, the last element in the set is not properly initializ
- CVE-2025-69204Dec 30, 2025affected < 7.1.1.21-150600.3.35.1fixed 7.1.1.21-150600.3.35.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and cau
- CVE-2025-68950Dec 30, 2025affected < 7.1.1.21-150600.3.35.1fixed 7.1.1.21-150600.3.35.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, Magick fails to check for circular references between two MVGs, leading to a stack overflow. This is a DoS vulnerability, and any situation that allows readin
- CVE-2025-68618Dec 30, 2025affected < 7.1.1.21-150600.3.35.1fixed 7.1.1.21-150600.3.35.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, using Magick to read a malicious SVG file resulted in a DoS attack. Version 7.1.2-12 fixes the issue.
- CVE-2025-66628Dec 10, 2025affected < 7.1.1.21-150600.3.32.1fixed 7.1.1.21-150600.3.32.1
ImageMagick is a software suite to create, edit, compose, or convert bitmap images. In versions 7.1.2-9 and prior, the TIM (PSX TIM) image parser contains a critical integer overflow vulnerability in its ReadTIMImage function (coders/tim.c). The code reads width and height (16-bi
- CVE-2025-65955Dec 2, 2025affected < 7.1.1.21-150600.3.32.1fixed 7.1.1.21-150600.3.32.1
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family
Page 3 of 4