CVE-2025-69204

Updated: 2026-02-04 04:09:23.717535

Description:

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-12, in the WriteSVGImage function, using an int variable to store number_attributes caused an integer overflow. This, in turn, triggered a buffer overflow and caused a DoS attack. Version 7.1.2-12 fixes the issue.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x 0.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU ImageMagick 6.9.13.17 7.5 HIGH In Testing 2026-02-05 04:18:44
CentOS 7 ELS ImageMagick 6.9.10.68 7.5 HIGH In Testing 2026-02-09 10:25:46
Oracle Linux 7 ELS ImageMagick 6.9.10.68 7.5 HIGH In Testing 2026-02-09 10:25:47
TuxCare 9.6 ESU ImageMagick 6.9.13.17 7.5 HIGH In Testing 2026-02-05 04:18:43
Ubuntu 16.04 ELS ImageMagick 6.8.9.9-7 7.5 HIGH In Testing 2026-02-09 20:28:19
Ubuntu 18.04 ELS ImageMagick 6.9.7.4 7.5 HIGH In Testing 2026-02-09 20:28:18
Ubuntu 20.04 ELS ImageMagick 6.9.10.23 7.5 HIGH In Testing 2026-02-07 04:59:27