{"id":"CVE-2025-57803","aliases":["GHSA-mxvv-97wh-cfmm"],"url":"https://o3.security/vulnerability/CVE-2025-57803","summary":"ImageMagick (WriteBMPImage): 32-bit integer overflow when writing BMP scanline stride → heap buffer overflow","details":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2 for ImageMagick's 32-bit build, a 32-bit integer overflow in the BMP encoder’s scanline-stride computation collapses bytes_per_line (stride) to a tiny value while the per-row writer still emits 3 × width bytes for 24-bpp images. The row base pointer advances using the (overflowed) stride, so the first row immediately writes past its slot and into adjacent heap memory with attacker-controlled bytes. This is a classic, powerful primitive for heap corruption in common auto-convert pipelines. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.","published":"2025-08-26T17:25:59.148Z","modified":"2026-08-08T08:26:50.112274Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"NuGet","name":"Magick.NET-Q16-AnyCPU","fixedVersion":"14.8.1"},{"ecosystem":"NuGet","name":"Magick.NET-Q16-HDRI-AnyCPU","fixedVersion":"14.8.1"},{"ecosystem":"NuGet","name":"Magick.NET-Q16-HDRI-x86","fixedVersion":"14.8.1"},{"ecosystem":"NuGet","name":"Magick.NET-Q16-x86","fixedVersion":"14.8.1"},{"ecosystem":"NuGet","name":"Magick.NET-Q8-AnyCPU","fixedVersion":"14.8.1"},{"ecosystem":"NuGet","name":"Magick.NET-Q8-x86","fixedVersion":"14.8.1"}],"fix":{"url":"https://github.com/ImageMagick/ImageMagick/commit/2c55221f4d38193adcb51056c14cf238fbcc35d7","label":"ImageMagick/ImageMagick@2c55221"},"references":[{"type":"WEB","url":"https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1"},{"type":"WEB","url":"https://lists.debian.org/debian-lts-announce/2025/09/msg00012.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/57xxx/CVE-2025-57803.json"},{"type":"ADVISORY","url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-mxvv-97wh-cfmm"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-57803"},{"type":"FIX","url":"https://github.com/ImageMagick/ImageMagick/commit/2c55221f4d38193adcb51056c14cf238fbcc35d7"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T08:26:50.112274Z"}}