ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's magick mogrify command, specifying multiple consecutive %d format specifiers in a filename template causes internal pointer arithmetic to generate an address below the beginning of the stack buffer, resulting in a stack overflow through vsnprintf(). Versions 7.1.2-0 and 6.9.13-26 fix the issue.
{
"cwe_ids": [
"CWE-124"
]
}[
{
"signature_type": "Function",
"digest": {
"function_hash": "182571243485465185900685937843774356463",
"length": 2590.0
},
"target": {
"file": "MagickCore/image.c",
"function": "InterpretImageFilename"
},
"source": "https://github.com/imagemagick/imagemagick/commit/66dc8f51c11b0ae1f1cdeacd381c3e9a4de69774",
"id": "CVE-2025-53101-9ef56c39",
"deprecated": false,
"signature_version": "v1"
},
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"33369542061393615056057609969638345659",
"184433310014570915510280775530083776256",
"92643362745098953169897505474450987254",
"223545190099778175927364189446236910838",
"24639001528345301698596952108441412724",
"154782676886582697314150768088090688010",
"59897040140485445174121324659573473187",
"101631689049611654313486323136922542735",
"37560204233120728103644333047285230833",
"168806550499176044177341556783886023640",
"203826750169934232432664171744242906440",
"63454920158817206346738749975636965757",
"196080570755634391010861913444436058161",
"143559768759288593844945581187370394660",
"331648285325892583600580715831962053299",
"59940605195700152395099964425411405892",
"293506528191132035835979187219100786576",
"214745457094461661857092416509828457938",
"10532438786860594398380005060816554022",
"77800108780179310344312574259338612419",
"183479371399575144561460152456978895091",
"273526454642708059673657789519756276349"
]
},
"target": {
"file": "MagickCore/image.c"
},
"source": "https://github.com/imagemagick/imagemagick/commit/66dc8f51c11b0ae1f1cdeacd381c3e9a4de69774",
"id": "CVE-2025-53101-cb4b2332",
"deprecated": false,
"signature_version": "v1"
}
]