#VU119820 Integer overflow in ImageMagick - CVE-2025-66628
Published: December 10, 2025
ImageMagick
ImageMagick.org
Description
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to integer overflow in TIM decoder within the ReadTIMImage() function in coders/tim.c. A remote attacker can pass specially crafted image data to the application, trigger an integer overflow and read sensitive information.
The vulnerability affects 32-bit systems only.