Debian Imagemagick vulnerabilities
674 known vulnerabilities affecting debian/imagemagick.
Total CVEs
674
CISA KEV
3
actively exploited
Public exploits
12
Exploited in wild
4
Severity breakdown
CRITICAL24HIGH138MEDIUM255LOW257
Vulnerabilities
Page 29 of 34
CVE-2020-27750P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27750 [MEDIUM] CVE-2020-27750: imagemagick - A flaw was found in ImageMagick in MagickCore/colorspace-private.h and MagickCor...
A flaw was found in ImageMagick in MagickCore/colorspace-private.h and MagickCore/quantum.h. An attacker who submits a crafted file that is processed by ImageMagick could trigger undefined behavior in the form of values outside the range of type `unsigned char` and math division by zero. This would most likely lead to an impact to application availability, but
debian
CVE-2021-20176P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.57+dfsg-1 (bookworm)2021
CVE-2021-20176 [MEDIUM] CVE-2021-20176: imagemagick - A divide-by-zero flaw was found in ImageMagick 6.9.11-57 and 7.0.10-57 in gem.c....
A divide-by-zero flaw was found in ImageMagick 6.9.11-57 and 7.0.10-57 in gem.c. This flaw allows an attacker who submits a crafted file that is processed by ImageMagick to trigger undefined behavior through a division by zero. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.57+dfsg-1)
bu
debian
CVE-2020-27756P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-27756 [MEDIUM] CVE-2020-27756: imagemagick - In ParseMetaGeometry() of MagickCore/geometry.c, image height and width calculat...
In ParseMetaGeometry() of MagickCore/geometry.c, image height and width calculations can lead to divide-by-zero conditions which also lead to undefined behavior. This flaw can be triggered by a crafted input file processed by ImageMagick and could impact application availability. The patch uses multiplication in addition to the function `PerceptibleReciprocal(
debian
CVE-2026-31853P4MEDIUMCVSS 5.7fixed in imagemagick 8:7.1.2.16+dfsg1-1 (forky)2026
CVE-2026-31853 [MEDIUM] CVE-2026-31853: imagemagick - ImageMagick is free and open-source software used for editing and manipulating d...
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, an overflow on 32-bit systems can cause a crash in the SFW decoder when processing extremely large images. This vulnerability is fixed in 7.1.2-16 and 6.9.13-41.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 8:7
debian
CVE-2017-15218P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-15218 [MEDIUM] CVE-2017-15218: imagemagick - ImageMagick 7.0.7-2 has a memory leak in ReadOneJNGImage in coders/png.c.
ImageMagick 7.0.7-2 has a memory leak in ReadOneJNGImage in coders/png.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3)
bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3)
forky: resolved (fixed in 8:6.9.9.34+dfsg-3)
sid: resolved (fixed in 8:6.9.9.34+dfsg-3)
trixie: resolved (fixed in 8:6.9.9.34+dfsg-3)
debian
CVE-2017-15217P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-15217 [MEDIUM] CVE-2017-15217: imagemagick - ImageMagick 7.0.7-2 has a memory leak in ReadSGIImage in coders/sgi.c.
ImageMagick 7.0.7-2 has a memory leak in ReadSGIImage in coders/sgi.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3)
bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3)
forky: resolved (fixed in 8:6.9.9.34+dfsg-3)
sid: resolved (fixed in 8:6.9.9.34+dfsg-3)
trixie: resolved (fixed in 8:6.9.9.34+dfsg-3)
debian
CVE-2017-14533P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-14533 [MEDIUM] CVE-2017-14533: imagemagick - ImageMagick 7.0.6-6 has a memory leak in ReadMATImage in coders/mat.c.
ImageMagick 7.0.6-6 has a memory leak in ReadMATImage in coders/mat.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3)
bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3)
forky: resolved (fixed in 8:6.9.9.34+dfsg-3)
sid: resolved (fixed in 8:6.9.9.34+dfsg-3)
trixie: resolved (fixed in 8:6.9.9.34+dfsg-3)
debian
CVE-2017-8830P4LOWCVSS 6.5fixed in imagemagick 8:6.9.7.4+dfsg-7 (bookworm)2017
CVE-2017-8830 [MEDIUM] CVE-2017-8830: imagemagick - In ImageMagick 7.0.5-6, the ReadBMPImage function in bmp.c:1379 allows attackers...
In ImageMagick 7.0.5-6, the ReadBMPImage function in bmp.c:1379 allows attackers to cause a denial of service (memory leak) via a crafted file.
Scope: local
bookworm: resolved (fixed in 8:6.9.7.4+dfsg-7)
bullseye: resolved (fixed in 8:6.9.7.4+dfsg-7)
forky: resolved (fixed in 8:6.9.7.4+dfsg-7)
sid: resolved (fixed in 8:6.9.7.4+dfsg-7)
trixie: resolved (fixed in
debian
CVE-2017-13062P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-13062 [MEDIUM] CVE-2017-13062: imagemagick - In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function fo...
In ImageMagick 7.0.6-6, a memory leak vulnerability was found in the function formatIPTC in coders/meta.c, which allows attackers to cause a denial of service (WriteMETAImage memory consumption) via a crafted file.
Scope: local
bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3)
bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3)
forky: resolved (fixed in 8:6.9.9.34+d
debian
CVE-2017-9261P4LOWCVSS 6.5fixed in imagemagick 8:6.9.7.4+dfsg-10 (bookworm)2017
CVE-2017-9261 [MEDIUM] CVE-2017-9261: imagemagick - In ImageMagick 7.0.5-6 Q16, the ReadMNGImage function in coders/png.c allows att...
In ImageMagick 7.0.5-6 Q16, the ReadMNGImage function in coders/png.c allows attackers to cause a denial of service (memory leak) via a crafted file.
Scope: local
bookworm: resolved (fixed in 8:6.9.7.4+dfsg-10)
bullseye: resolved (fixed in 8:6.9.7.4+dfsg-10)
forky: resolved (fixed in 8:6.9.7.4+dfsg-10)
sid: resolved (fixed in 8:6.9.7.4+dfsg-10)
trixie: resolved
debian
CVE-2018-17967P4LOWCVSS 6.5fixed in imagemagick 8:6.9.10.14+dfsg-1 (bookworm)2018
CVE-2018-17967 [MEDIUM] CVE-2018-17967: imagemagick - ImageMagick 7.0.7-28 has a memory leak vulnerability in ReadBGRImage in coders/b...
ImageMagick 7.0.7-28 has a memory leak vulnerability in ReadBGRImage in coders/bgr.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.10.14+dfsg-1)
bullseye: resolved (fixed in 8:6.9.10.14+dfsg-1)
forky: resolved (fixed in 8:6.9.10.14+dfsg-1)
sid: resolved (fixed in 8:6.9.10.14+dfsg-1)
trixie: resolved (fixed in 8:6.9.10.14+dfsg-1)
debian
CVE-2009-3736P4LOWCVSS 6.9fixed in clamav 0.95+dfsg-1 (bookworm)2009
CVE-2009-3736 [MEDIUM] CVE-2009-3736: bochs - ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham ...
ltdl.c in libltdl in GNU Libtool 1.5.x, and 2.2.6 before 2.2.6b, as used in Ham Radio Control Libraries, Q, and possibly other products, attempts to open a .la file in the current working directory, which allows local users to gain privileges via a Trojan horse file.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
debian
CVE-2010-4167P4LOWCVSS 6.9fixed in imagemagick 8:6.6.0.4-3 (bookworm)2010
CVE-2010-4167 [MEDIUM] CVE-2010-4167: imagemagick - Untrusted search path vulnerability in configure.c in ImageMagick before 6.6.5-5...
Untrusted search path vulnerability in configure.c in ImageMagick before 6.6.5-5, when MAGICKCORE_INSTALLED_SUPPORT is defined, allows local users to gain privileges via a Trojan horse configuration file in the current working directory.
Scope: local
bookworm: resolved (fixed in 8:6.6.0.4-3)
bullseye: resolved (fixed in 8:6.6.0.4-3)
forky: resolved (fixed in 8:6
debian
CVE-2017-13060P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-13060 [MEDIUM] CVE-2017-13060: imagemagick - In ImageMagick 7.0.6-5, a memory leak vulnerability was found in the function Re...
In ImageMagick 7.0.6-5, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.
Scope: local
bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3)
bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3)
forky: resolved (fixed in 8:6.9.9.34+dfsg-3)
sid: resolved (fixed in 8:6.
debian
CVE-2017-12433P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-12433 [MEDIUM] CVE-2017-12433: imagemagick - In ImageMagick 7.0.6-1, a memory leak vulnerability was found in the function Re...
In ImageMagick 7.0.6-1, a memory leak vulnerability was found in the function ReadPESImage in coders/pes.c, which allows attackers to cause a denial of service, related to ResizeMagickMemory in memory.c.
Scope: local
bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3)
bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3)
forky: resolved (fixed in 8:6.9.9.34+dfsg-3)
sid:
debian
CVE-2017-14326P4LOWCVSS 6.5fixed in imagemagick 8:6.9.9.34+dfsg-3 (bookworm)2017
CVE-2017-14326 [MEDIUM] CVE-2017-14326: imagemagick - In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the functio...
In ImageMagick 7.0.7-1 Q16, a memory leak vulnerability was found in the function ReadMATImage in coders/mat.c, which allows attackers to cause a denial of service via a crafted file.
Scope: local
bookworm: resolved (fixed in 8:6.9.9.34+dfsg-3)
bullseye: resolved (fixed in 8:6.9.9.34+dfsg-3)
forky: resolved (fixed in 8:6.9.9.34+dfsg-3)
sid: resolved (fixed in
debian
CVE-2023-5341P4MEDIUMCVSS 6.2fixed in imagemagick 8:6.9.11.60+dfsg-1.6+deb12u1 (bookworm)2023
CVE-2023-5341 [MEDIUM] CVE-2023-5341: imagemagick - A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.
A heap use-after-free flaw was found in coders/bmp.c in ImageMagick.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.60+dfsg-1.6+deb12u1)
bullseye: resolved (fixed in 8:6.9.11.60+dfsg-1.3+deb11u3)
forky: resolved (fixed in 8:6.9.12.98+dfsg1-2)
sid: resolved (fixed in 8:6.9.12.98+dfsg1-2)
trixie: resolved (fixed in 8:6.9.12.98+dfsg1-2)
debian
CVE-2015-8898P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-7 (bookworm)2015
CVE-2015-8898 [MEDIUM] CVE-2015-8898: imagemagick - The WriteImages function in magick/constitute.c in ImageMagick before 6.9.2-4 al...
The WriteImages function in magick/constitute.c in ImageMagick before 6.9.2-4 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted image file.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-7)
bullseye: resolved (fixed in 8:6.8.9.9-7)
forky: resolved (fixed in 8:6.8.9.9-7)
sid: resolved (fixed in 8:6.8.9.9-7)
trixie:
debian
CVE-2014-9845P4MEDIUMCVSS 5.5fixed in imagemagick 8:6.8.9.9-4 (bookworm)2014
CVE-2014-9845 [MEDIUM] CVE-2014-9845: imagemagick - The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers...
The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
Scope: local
bookworm: resolved (fixed in 8:6.8.9.9-4)
bullseye: resolved (fixed in 8:6.8.9.9-4)
forky: resolved (fixed in 8:6.8.9.9-4)
sid: resolved (fixed in 8:6.8.9.9-4)
trixie: resolved (fixed in 8:6.8.9.9-4)
debian
CVE-2020-10251P4LOWCVSS 5.5fixed in imagemagick 8:6.9.11.24+dfsg-1 (bookworm)2020
CVE-2020-10251 [MEDIUM] CVE-2020-10251: imagemagick - In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the Read...
In ImageMagick 7.0.9, an out-of-bounds read vulnerability exists within the ReadHEICImageByID function in coders\heic.c. It can be triggered via an image with a width or height value that exceeds the actual size of the image.
Scope: local
bookworm: resolved (fixed in 8:6.9.11.24+dfsg-1)
bullseye: resolved (fixed in 8:6.9.11.24+dfsg-1)
forky: resolved (fixed in
debian