cbcvebase.
CVE-2025-46393
published 2025-04-23

CVE-2025-46393: In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary…

PriorityP428medium5.3CVSS 3.1
AVNACLPRNUINSUCNILAN
EPSS
0.39%
31.9th percentile
In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).

Affected

4 ranges
VendorProductVersion rangeFixed in
debianimagemagick< imagemagick 8:7.1.1.46+dfsg1-1 (forky)imagemagick 8:7.1.1.46+dfsg1-1 (forky)
imagemagickimagemagick< 7.1.1-447.1.1-44
imagemagickimagemagick>= 0 < 8:7.1.1.43+dfsg1-1+deb13u18:7.1.1.43+dfsg1-1+deb13u1
imagemagickimagemagick>= 0 < 8:7.1.1.46+dfsg1-18:7.1.1.46+dfsg1-1

CVSS provenance

nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
osv5.3MEDIUM
vendor_debian2.9LOW
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.