suse · CVE-2025-53014

Quick triage

Priority: medium Published: 2025-08-05 23:14:55 UTC Updated: 2026-03-05 00:31:21 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2025-53014 severity moderate: SUSE including 79 source package names (GraphicsMagick, GraphicsMagick-devel, …), 113 product×package rows across 12 product lines (SUSE Linux Enterprise Module for Desktop Applications 15 SP6, SUSE Linux Enterprise Module for Desktop Applications 15 SP7, … (12 product lines)): Fixed 89, Known Not Affected 24.

Description:

ImageMagick is free and open-source software used for editing and manipulating digital images. Versions prior to 7.1.2-0 and 6.9.13-26 have a heap buffer overflow in the `InterpretImageFilename` function. The issue stems from an off-by-one error that causes out-of-bounds memory access when processing format strings containing consecutive percent signs (`%%`). Versions 7.1.2-0 and 6.9.13-26 fix the issue.

cvelogic Threat Intelligence