cbcvebase.
CVE-2025-65955
published 2025-12-02

CVE-2025-65955: ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in…

PriorityP427medium6.1CVSS 3.1
AVLACLPRLUINSUCNILAH
EPSS
0.14%
4.0th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Clearing a font family calls RelinquishMagickMemory on _drawInfo->font, freeing the font string but leaving _drawInfo->font pointing to freed memory while _drawInfo->family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo->font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo->font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. This vulnerability is fixed in 7.1.2-9 and 6.9.13-34.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianimagemagick< imagemagick 8:6.9.11.60+dfsg-1.6+deb12u5 (bookworm)imagemagick 8:6.9.11.60+dfsg-1.6+deb12u5 (bookworm)
imagemagickimagemagick< 6.9.13-346.9.13-34
imagemagickimagemagick
imagemagickimagemagick>= 0 < 8:6.9.11.60+dfsg-1.3+deb11u88:6.9.11.60+dfsg-1.3+deb11u8
imagemagickimagemagick>= 0 < 8:6.9.11.60+dfsg-1.6+deb12u58:6.9.11.60+dfsg-1.6+deb12u5
imagemagickimagemagick>= 0 < 8:7.1.1.43+dfsg1-1+deb13u48:7.1.1.43+dfsg1-1+deb13u4
imagemagickimagemagick>= 0 < 8:7.1.2.12+dfsg1-18:7.1.2.12+dfsg1-1
imagemagickimagemagick>= 7.0.0-0 < 7.1.2-97.1.2-9

CVSS provenance

nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
osv6.1MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.