<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:15:20 +0000</lastBuildDate>
    <item>
      <title>bdu:2025-11265</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-11265</link>
      <description>bdu:2025-11265</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-11265</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0969 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</link>
      <description>certfr-2025-avi-0969</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0969</guid>
    </item>
    <item>
      <title>EUVD-2026-272019</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-272019</link>
      <description>EUVD-2026-272019</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-272019</guid>
    </item>
    <item>
      <title>fkie_cve-2025-57803</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-57803</link>
      <description>&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick&amp;#39;s 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick&amp;#39;s 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-57803</guid>
    </item>
    <item>
      <title>GHSA-mxvv-97wh-cfmm — ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mxvv-97wh-cfmm</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: Magick.NET-Q16-AnyCPU, NuGet: Magick.NET-Q16-HDRI-AnyCPU, NuGet: Magick.NET-Q16-HDRI-x86, NuGet: Magick.NET-Q16-x86, NuGet: Magick.NET-Q8-AnyCPU, NuGet: Magick.NET-Q8-x86&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses `bytes_per_line` (stride) to a tiny value while the per-row writer still emits `3 × width` bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines.&lt;/p&gt;
&lt;p&gt;- **Impact:** Attacker-controlled heap out-of-bounds (OOB) write during conversion **to BMP**.
    
- **Surface:** Typical upload → normalize/thumbnail → `magick ... out.bmp` workers.
    
- **32-bit:** **Vulnerable** (reproduced with ASan).
    
- **64-bit:** Safe from this specific integer overflow (IOF) by arithmetic, but still add product/size guards.
    
- **Proposed severity:** **Critical 9.8** (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Scope &amp;amp; Affected Builds&lt;/p&gt;
&lt;p&gt;- **Project:** ImageMagick (BMP writer path, `WriteBMPImage` in `coders/bmp.c`).
    
- **Commit under test:** `3fcd081c0278427fc0e8ac40ef75c0a1537792f7`
    
- **Version string from the run:** `ImageMagick 7.1.2-0 Q8 i686 9bde76f1d:20250712`
    
- **Architecture:** 32-bit i686 (**`sizeof(size_t) == 4`**) with ASan/UBSan.
    
- **Note on other versions:** Any release/branch with the same stride arithmetic and row loop is likely affected on 32-bit.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Root Cause (with code anchors)&lt;/p&gt;
&lt;p&gt;### Stride computation (writ…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; NuGet: Magick.NET-Q16-AnyCPU, NuGet: Magick.NET-Q16-HDRI-AnyCPU, NuGet: Magick.NET-Q16-HDRI-x86, NuGet: Magick.NET-Q16-x86, NuGet: Magick.NET-Q8-AnyCPU, NuGet: Magick.NET-Q8-x86&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses `bytes_per_line` (stride) to a tiny value while the per-row writer still emits `3 × width` bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines.&lt;/p&gt;
&lt;p&gt;- **Impact:** Attacker-controlled heap out-of-bounds (OOB) write during conversion **to BMP**.
    
- **Surface:** Typical upload → normalize/thumbnail → `magick ... out.bmp` workers.
    
- **32-bit:** **Vulnerable** (reproduced with ASan).
    
- **64-bit:** Safe from this specific integer overflow (IOF) by arithmetic, but still add product/size guards.
    
- **Proposed severity:** **Critical 9.8** (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Scope &amp;amp; Affected Builds&lt;/p&gt;
&lt;p&gt;- **Project:** ImageMagick (BMP writer path, `WriteBMPImage` in `coders/bmp.c`).
    
- **Commit under test:** `3fcd081c0278427fc0e8ac40ef75c0a1537792f7`
    
- **Version string from the run:** `ImageMagick 7.1.2-0 Q8 i686 9bde76f1d:20250712`
    
- **Architecture:** 32-bit i686 (**`sizeof(size_t) == 4`**) with ASan/UBSan.
    
- **Note on other versions:** Any release/branch with the same stride arithmetic and row loop is likely affected on 32-bit.&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;## Root Cause (with code anchors)&lt;/p&gt;
&lt;p&gt;### Stride computation (writ…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mxvv-97wh-cfmm</guid>
    </item>
    <item>
      <title>OESA-2025-2193 — ImageMagick security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2193</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: ImageMagick&lt;/p&gt;
&lt;p&gt;Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.(CVE-2025-55004)&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, when preparing to transform from Log to sRGB colorspaces, the logmap construction fails to handle cases where the reference-black or reference-white value is larger than 1024. This leads to corrupting memory beyond the end of the allocated logmap buffer. This issue has been patched in version 7.1.2-1.(CVE-2025-55005)&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (i…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP3: ImageMagick&lt;/p&gt;
&lt;p&gt;Use ImageMagick to create, edit, compose, or convert bitmap images. It can read and write images in a variety of formats (over 200) including PNG, JPEG, GIF, HEIC, TIFF, DPX, EXR, WebP, Postscript, PDF, and SVG. Use ImageMagick to resize, flip, mirror, rotate, distort, shear and transform images, adjust image colors, apply various special effects, or draw text, lines, polygons, ellipses and Bézier curves.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1.(CVE-2025-55004)&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, when preparing to transform from Log to sRGB colorspaces, the logmap construction fails to handle cases where the reference-black or reference-white value is larger than 1024. This leads to corrupting memory beyond the end of the allocated logmap buffer. This issue has been patched in version 7.1.2-1.(CVE-2025-55005)&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, the magnified size calculations in ReadOneMNGIMage (i…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2193</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15498-1 — ImageMagick-7.1.2.2-2.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15498-1</link>
      <description>&lt;p&gt;ImageMagick-7.1.2.2-2.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ImageMagick-7.1.2.2-2.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15498-1</guid>
    </item>
    <item>
      <title>RHSA-2025:16313 — Red Hat Security Advisory: ImageMagick security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:16313</link>
      <description>&lt;p&gt;imagemagick: ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;imagemagick: ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:16313</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03150-1 — Security update for ImageMagick</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03150-1</link>
      <description>&lt;p&gt;Security update for ImageMagick&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for ImageMagick&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03150-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-57803</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-57803</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: imagemagick, Ubuntu:Pro:16.04:LTS: imagemagick, Ubuntu:Pro:18.04:LTS: imagemagick, Ubuntu:Pro:20.04:LTS: imagemagick, Ubuntu:Pro:22.04:LTS: imagemagick, Ubuntu:Pro:24.04:LTS: imagemagick&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick&amp;#39;s 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: imagemagick, Ubuntu:Pro:16.04:LTS: imagemagick, Ubuntu:Pro:18.04:LTS: imagemagick, Ubuntu:Pro:20.04:LTS: imagemagick, Ubuntu:Pro:22.04:LTS: imagemagick, Ubuntu:Pro:24.04:LTS: imagemagick&lt;/p&gt;
&lt;p&gt;ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick&amp;#39;s 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-57803</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1906 — ImageMagick: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1906</link>
      <description>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in ImageMagick ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, vertrauliche Informationen offenzulegen und andere nicht näher definierte Angriffe durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter Angreifer kann mehrere Schwachstellen in ImageMagick ausnutzen, um einen Denial-of-Service-Zustand zu erzeugen, beliebigen Code auszuführen, erweiterte Berechtigungen zu erlangen, vertrauliche Informationen offenzulegen und andere nicht näher definierte Angriffe durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1906</guid>
    </item>
  </channel>
</rss>
