Write-what-where Condition
CVE-2025-55298
Summary
ImageMagick is free and open-source software used for editing and manipulating digital images. Affected versions of ImageMagick are CPP package versions prior to 6.9.13-28 and 7.1.2-2, as well as NuGet packages versions prior to 14.8.1, where a Format String bug vulnerability exists in "InterpretImageFilename()" function where user input is directly passed to "FormatLocaleString" without proper sanitization. An attacker can overwrite arbitrary memory regions, enabling a wide range of attacks from Heap Overflow to Remote Code Execution.
- LOW
- NETWORK
- HIGH
- UNCHANGED
- NONE
- LOW
- HIGH
- HIGH
CWE-123 - Write-what-where Condition
Any condition where the attacker has the ability to write an arbitrary value to an arbitrary location, often as the result of a buffer overflow.
References
Advisory Timeline
- Published