Uncontrolled Recursion
CVE-2025-68618
Summary
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick version 7.1.2-12 and 6.9.13-37 and Magick.NET version 14.10.1, using Magick to read a malicious SVG file resulted in a Denial-of-Service attack. ImageMagick version 7.1.2-12 and 6.9.13-37 and Magick.NET version 14.10.1 fixes the issue.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- NONE
- HIGH
CWE-674 - Uncontrolled Recursion
The product does not properly control the amount of recursion which takes place, consuming excessive resources, such as allocated memory or the program stack.
References
Advisory Timeline
- Published