CVE-2025-68469
published 2025-12-18CVE-2025-68469: ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a…
PriorityP411low3.3CVSS 3.1
AVLACLPRNUIRSUCNINAL
EPSS
0.18%
8.0th percentile
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | imagemagick | < imagemagick 8:6.9.11.60+dfsg-1.6+deb12u5 (bookworm) | imagemagick 8:6.9.11.60+dfsg-1.6+deb12u5 (bookworm) |
| imagemagick | imagemagick | < 7.1.1-14 | 7.1.1-14 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.3+deb11u8 | 8:6.9.11.60+dfsg-1.3+deb11u8 |
| imagemagick | imagemagick | >= 0 < 8:6.9.11.60+dfsg-1.6+deb12u5 | 8:6.9.11.60+dfsg-1.6+deb12u5 |
| imagemagick | imagemagick | >= 0 < 8:6.9.12.98+dfsg1-2 | 8:6.9.12.98+dfsg1-2 |
| imagemagick | imagemagick | >= 0 < 8:6.9.12.98+dfsg1-2 | 8:6.9.12.98+dfsg1-2 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
nvdv4.02.0LOWCVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv2.0LOW
vendor_debian2.0LOW
vendor_redhat2.0LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-68469: ImageMagick is free and open-source software used for editing and manipulating digital images
osv·2025-12-18·CVSS 2.0
CVE-2025-68469 [LOW] CVE-2025-68469: ImageMagick is free and open-source software used for editing and manipulating digital images
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.
GHSA
ImageMagick has a heap-buffer-overflow
ghsa·2025-08-25
CVE-2025-68469 [LOW] CWE-122 ImageMagick has a heap-buffer-overflow
ImageMagick has a heap-buffer-overflow
### Summary
While Processing a crafted TIFF file, imagemagick crashes.
### Details
Following is the imagemagick version:
```
imagemagick_git/build_26jun23/bin/magick --version
Version: ImageMagick 7.1.1-13 (Beta) Q16-HDRI x86_64 56f478940:20230625 https://imagemagick.org
Copyright: (C) 1999 ImageMagick Studio LLC
License: https://imagemagick.org/script/license.php
Features: Cipher DPC HDRI
Delegates (built-in): fontconfig freetype jbig jng jpeg lcms lzma pangocairo png tiff webp x xml zlib
Compiler: gcc (4.2)
```
### PoC
issue can be replicated with following command with provided POC file(sent over email):
```bash
magick poc.tiff /dev/null
```
### Impact
This can lead to application crash.
### Credits
Please give credits to Hardik shah of Vehere (
OSV
ImageMagick has a heap-buffer-overflow
osv·2025-08-25
CVE-2025-68469 [LOW] ImageMagick has a heap-buffer-overflow
ImageMagick has a heap-buffer-overflow
### Summary
While Processing a crafted TIFF file, imagemagick crashes.
### Details
Following is the imagemagick version:
```
imagemagick_git/build_26jun23/bin/magick --version
Version: ImageMagick 7.1.1-13 (Beta) Q16-HDRI x86_64 56f478940:20230625 https://imagemagick.org
Copyright: (C) 1999 ImageMagick Studio LLC
License: https://imagemagick.org/script/license.php
Features: Cipher DPC HDRI
Delegates (built-in): fontconfig freetype jbig jng jpeg lcms lzma pangocairo png tiff webp x xml zlib
Compiler: gcc (4.2)
```
### PoC
issue can be replicated with following command with provided POC file(sent over email):
```bash
magick poc.tiff /dev/null
```
### Impact
This can lead to application crash.
### Credits
Please give credits to Hardik shah of Vehere (
Red Hat
ImageMagick: heap-based buffer overflow via a crafted TIFF file
vendor_redhat·2025-12-18·CVSS 2.0
CVE-2025-68469 [LOW] CWE-122 ImageMagick: heap-based buffer overflow via a crafted TIFF file
ImageMagick: heap-based buffer overflow via a crafted TIFF file
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.
A flaw was found in ImageMagick. Processing a specially crafted TIFF file can cause a heap-based buffer overflow and result in a denial of service.
Statement: To exploit this issue, an attacker needs to convince a user to process a crafted TIFF file with ImageMagick. Additionally, this vulnerability can cause a heap-based buffer overflow, but there is no evidence of memory corruption or code execution, limiting the impact to an application crash. Due to these reasons, this flaw has been rated with a low severity.
Debian
CVE-2025-68469: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
vendor_debian·2025·CVSS 2.0
CVE-2025-68469 [LOW] CVE-2025-68469: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.1-14, ImageMagick crashes when processing a crafted TIFF file. Version 7.1.1-14 fixes the issue.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6+deb12u5)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u8)
forky: resolved (fixed in 8:6.9.12.98+dfsg1-2)
sid: resolved (fixed in 8:6.9.12.98+dfsg1-2)
trixie: resolved (fixed in 8:6.9.12.98+dfsg1-2)
No detection rules found.
No public exploits indexed.
2025-12-18
Published