ECHO-eab7-3e17-b4f3

See a problem?
Import Source
https://advisory.echohq.com/osv/ECHO-eab7-3e17-b4f3.json
JSON Data
https://api.osv.dev/v1/vulns/ECHO-eab7-3e17-b4f3
Upstream
Withdrawn
2025-10-28T08:30:08Z
Published
2025-09-15T01:08:34Z
Modified
2026-09-15T03:33:35Z
Summary
The cve is that when modifying a jpeg image with imagemagic, the original image thumbnail might not modify the EXIF thumbnail. But there are ways to remove the EXIF profile with like with a convert --strip command. It's just something an application needs to handle. The debian bug was closed and the upstream said it won't fix it.
Details
References

Affected packages

Echo / imagemagick

Package

Name
imagemagick
Purl
pkg:deb/echo/imagemagick

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
8:7.1.1.43+dfsg1-1+deb13u2

Database specific

source
"https://advisory.echohq.com/osv/ECHO-eab7-3e17-b4f3.json"