ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in InterpretImageFilename function where user input is directly passed to FormatLocaleString without proper sanitization. An attacker can overwrite arbitrary memory regions, enabling a wide range of attacks from heap overflow to remote code execution. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.
{
"cwe_ids": [
"CWE-123",
"CWE-134"
]
}[
{
"source": "https://github.com/imagemagick/imagemagick/commit/439b362b93c074eea6c3f834d84982b43ef057d5",
"target": {
"function": "InterpretImageFilename",
"file": "MagickCore/image.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-55298-08dad9bb",
"signature_type": "Function",
"digest": {
"length": 2423.0,
"function_hash": "203154114098319073765007390346548498804"
}
},
{
"source": "https://github.com/imagemagick/imagemagick/commit/439b362b93c074eea6c3f834d84982b43ef057d5",
"target": {
"file": "MagickCore/image.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-55298-09d83caf",
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"10685655258371385588661223041628302753",
"165249012698808506757867210299884443055",
"228917513246707470161278283225314070369",
"231168465612498823660345252192325607681",
"191485976778451351382884515004693640899",
"328452766036847001217609598595900066706",
"104447800950460882489077283834908456767",
"329070562278624302075887385494851604193",
"302436216128789544317192868591633147498",
"274519963126580738959121888341165216784",
"269839394030102788539093188160524678928",
"293400200304377958609532663108228563914",
"309284435881448524748999297520503269346",
"61925192225354002048292956442629208851",
"161111711136754256008707988400435195442",
"277096490399429866268414842524802227231",
"82796436621892934938547198895836131315",
"114337781389225092914527295667223887406",
"195689729879822317671341471881502643147",
"232794369188494762240221134477848341335",
"121610347989828653879317732780689828507",
"232605881279803764549739787935247886221",
"318873579762505949567354053291632308185",
"49928733467883672417777030264357217310",
"233389062052025913285300290461209499248",
"94467147304143934912237817628683459297",
"272347408597850055113336959753876131037",
"333233224521551534823341905894629394374",
"234112578658270638032522555580953644686",
"162672433488937781574916520812072502229",
"224982012705247283348512755278933127877",
"336152882870932446217722843394229503097",
"113290311430929485380998411820248508765",
"88893928230435992172129278644822699301",
"332632962303422922735602590556850293271",
"83555987299288769253890963744924856612",
"238940949499957487069868710051676296176",
"179830239918284678765207353055852447760",
"111845807964777979276578145328413032882",
"181553584423926593773808290327713886186",
"298891184779583866152316502184433549430",
"114498579428457686773461344776518085948",
"270215130762096039238643349977121455753",
"280236783309850278892845295964184740120",
"289227467936286125463385325586214481146",
"16030432218638950051374585290755262023",
"210170548016361832190339019507905916792",
"257911366694643431765678820581884652968",
"329328731625747359127105977312048158029",
"93613665007146220277797090887952046046",
"208962213676047377988011100634149772341",
"69002963655560804576275599451362627805",
"63454920158817206346738749975636965757",
"196080570755634391010861913444436058161",
"90402833192047306060477032242433275025",
"209743958554029297140103065069315498208",
"231661560737349050766778878718441217557",
"116055422195470080492810059705005291133",
"49747642820979422459471799281992700554",
"135700419408385626370919290768911238552",
"226756071717463861506358553495950022111",
"100042897138627337089445109707073678741",
"241368559078953933333987241934309301500",
"50927914678320344661834888481574890559",
"34358810873806419238145786986753700434",
"309272842558291299095497921348116710667",
"194524200121631183662008790296015120271",
"66310617184931960129086427477585253019",
"99131021540687986140545008592750036962",
"274737027736776292890597166609437248259",
"314742740126216660066539094374200240804",
"240483324085092040524395091162275987982",
"16716414859034691463708907597123464241",
"95615303596591420190568024993918645655",
"62453711722249355645534784361617930926",
"2732988362602123626655476943136096984",
"104450956965347761698150331578860493414",
"322131269490544373764809193201774449134",
"273405979659155056819344592237119998492",
"24390314602587881609841003858269250860",
"220101386331450559128026392960207389661",
"212843253024583470735182887380292076842",
"141408461582857368256841244438402275316",
"100001212235413480145373906268083650995",
"175628342850646747368778567677715821011",
"296351638369045675136798393346473724622",
"64420379868364543443584885723300842670",
"195671012115485235330096357009401784944",
"280036140090352577663282194096768512559",
"102694889311625904344056814836805635875",
"142884485101953350324616234290612030747",
"296532575451065619650002394258596285435",
"148132814082934705578808663362643181367",
"122070763850071826873767642565411690312",
"335973733795751322178344108957329464182",
"303463998793085017798314941888372933766",
"262700240016536891643127063421288536240",
"61276533365509694592740232564375844692",
"98420655211575937807466119042886866034",
"168291878923929040908955000597105304266",
"230253159622844319694996473208373025892",
"12038744923771033022223912302583387801",
"334394797854294428247179538241373546302",
"16005707821783007815482866254495297126",
"39302910621898167293865526273311332327",
"163365333947463192760216260292028193514",
"294499242268042958011862729104185851022",
"214850724187710280178872017591142505081",
"6688793479999963539472509205045129458",
"48809543901561610867071255703137649541",
"209286806121175417454138733431696180278",
"33476512551336690388166244326428808258",
"329071754932201752948128431804203897654",
"30974731805641867153134254009665804742",
"180500052790162488998498765577603879116",
"190712101947725989466171400816972587764"
]
}
},
{
"source": "https://github.com/imagemagick/imagemagick/commit/439b362b93c074eea6c3f834d84982b43ef057d5",
"target": {
"function": "PercentNInvalidOperation",
"file": "MagickCore/image.c"
},
"deprecated": false,
"signature_version": "v1",
"id": "CVE-2025-55298-991823b5",
"signature_type": "Function",
"digest": {
"length": 365.0,
"function_hash": "201479786465063284992666366636988957097"
}
}
]