Out-of-bounds read in GraphicsMagick - CVE-2025-32460

 

Out-of-bounds read in GraphicsMagick - CVE-2025-32460

Published: April 18, 2025


Vulnerability identifier: #VU107610
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-32460
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a heap-based buffer over-read in ReadJXLImage() function in coders/jxl.c, related to an ImportViewPixelArea call. A remote attacker can pass specially crafted image to the application and perform a denial of service attack.


Affected software

GraphicsMagick
Debian Linux
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Package Hub 15
openSUSE Leap
openEuler
GraphicsMagick-help
GraphicsMagick-perl
GraphicsMagick-devel
GraphicsMagick-debugsource
GraphicsMagick-debuginfo
GraphicsMagick-c++-devel
GraphicsMagick-c++
GraphicsMagick
libGraphicsMagick++-devel
libGraphicsMagick++-Q16-12
libGraphicsMagickWand-Q16-2-debuginfo
libGraphicsMagick++-Q16-12-debuginfo
libGraphicsMagickWand-Q16-2
libGraphicsMagick3-config
perl-GraphicsMagick-debuginfo
perl-GraphicsMagick
libGraphicsMagick-Q16-3-debuginfo
libGraphicsMagick-Q16-3
graphicsmagick (Debian package)

How to mitigate CVE-2025-32460

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

GraphicsMagick-help - update to 1.3.41-2
GraphicsMagick-perl - update to 1.3.41-2
GraphicsMagick-devel - update to 1.3.41-2
GraphicsMagick-debugsource - update to 1.3.41-2
GraphicsMagick-debuginfo - update to 1.3.41-2
GraphicsMagick-c++-devel - update to 1.3.41-2
GraphicsMagick-c++ - update to 1.3.41-2
GraphicsMagick - update to 1.3.41-2
libGraphicsMagick++-devel - update to 1.3.42-150600.3.7.1
libGraphicsMagick++-Q16-12 - update to 1.3.42-150600.3.7.1
libGraphicsMagickWand-Q16-2-debuginfo - update to 1.3.42-150600.3.7.1
libGraphicsMagick++-Q16-12-debuginfo - update to 1.3.42-150600.3.7.1
GraphicsMagick-devel - update to 1.3.42-150600.3.7.1
libGraphicsMagickWand-Q16-2 - update to 1.3.42-150600.3.7.1
libGraphicsMagick3-config - update to 1.3.42-150600.3.7.1
perl-GraphicsMagick-debuginfo - update to 1.3.42-150600.3.7.1
GraphicsMagick-debugsource - update to 1.3.42-150600.3.7.1
perl-GraphicsMagick - update to 1.3.42-150600.3.7.1
GraphicsMagick - update to 1.3.42-150600.3.7.1
libGraphicsMagick-Q16-3-debuginfo - update to 1.3.42-150600.3.7.1
GraphicsMagick-debuginfo - update to 1.3.42-150600.3.7.1
libGraphicsMagick-Q16-3 - update to 1.3.42-150600.3.7.1
graphicsmagick (Debian package) - update to 1.4+really1.3.40-4+deb12u1

External References

Related Security Bulletins