This update for ImageMagick fixes the following issues:
- CVE-2025-62594: unsigned underflow and division-by-zero can lead to OOB pointer arithmetic and process crash
(bsc#1252749).
- CVE-2025-57807: BlobStream Forward-Seek Under-Allocation (bsc#1249362).
- CVE-2025-62171: incomplete fix for integer overflow in BMP Decoder (bsc#1252282).
- CVE-2025-55298: format string bug vulnerability can lead to heap overflow (bsc#1248780).
- CVE-2025-57803: 32-bit integer overflow can lead to heap out-of-bounds (OOB) write (bsc#1248784).
- CVE-2025-55212: division-by-zero in ThumbnailImage() when passing a geometry string containing only a colon to
`montage -geometry` (bsc#1248767).
Patch instructions:
To install this openSUSE security update use the suse recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 16.0
zypper in -t patch openSUSE-Leap-16.0-105=1
- openSUSE Leap 16.0:
ImageMagick-7.1.2.0-160000.4.1
ImageMagick-config-7-SUSE-7.1.2.0-160000.4.1
ImageMagick-config-7-upstream-limited-7.1.2.0-160000.4.1
ImageMagick-config-7-upstream-open-7.1.2.0-160000.4.1
ImageMagick-config-7-upstream-secure-7.1.2.0-160000.4.1
ImageMagick-config-7-upstream-websafe-7.1.2.0-160000.4.1
ImageMagick-devel-7.1.2.0-160000.4.1
ImageMagick-doc-7.1.2.0-160000.4.1
ImageMagick-extra-7.1.2.0-160000.4.1
libMagick++-7_Q16HDRI5-7.1.2.0-160000.4.1
libMagick++-devel-7.1.2.0-160000.4.1
libMagickCore-7_Q16HDRI10-7.1.2.0-160000.4.1
libMagickWand-7_Q16HDRI10-7.1.2.0-160000.4.1
perl-PerlMagick-7.1.2.0-160000.4.1
* bsc#1248767
* bsc#1248780
* bsc#1248784
* bsc#1249362
* bsc#1252282
* bsc#1252749
References:
* https://www.suse.com/security/cve/CVE-2025-55212.html
* https://www.suse.com/security/cve/CVE-2025-55298.html
* https://www.suse.com/security/cve/CVE-2025-57803.html
* https://www.suse.com/security/cve/CVE-2025-57807.html
* https://www.suse.com/security/cve/CVE-2025-62171.html
* https://www.suse.com/security/cve/CVE-2025-62594.html
Get the latest Linux and open source security news straight to your inbox.