ALAS2023-2025-1182


Amazon Linux 2023 Security Advisory: ALAS2023-2025-1182
Advisory Released Date: 2025-09-15
Advisory Updated Date: 2025-09-15
Severity: Important

Issue Overview:

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, ImageMagick is vulnerable to heap-buffer overflow read around the handling of images with separate alpha channels when performing image magnification in ReadOneMNGIMage. This can likely be used to leak subsequent memory contents into the output image. This issue has been patched in version 7.1.2-1. (CVE-2025-55004)

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-1, when preparing to transform from Log to sRGB colorspaces, the logmap construction fails to handle cases where the reference-black or reference-white value is larger than 1024. This leads to corrupting memory beyond the end of the allocated logmap buffer. This issue has been patched in version 7.1.2-1. (CVE-2025-55005)

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-27 and 7.1.2-1, there is undefined behavior (function-type-mismatch) in splay tree cloning callback. This results in a deterministic abort under UBSan (DoS in sanitizer builds), with no crash in a non-sanitized build. This issue has been patched in versions 6.9.13-27 and 7.1.2-1. (CVE-2025-55160)

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to ImageMagick versions 6.9.13-28 and 7.1.2-2, a format string bug vulnerability exists in InterpretImageFilename function where user input is directly passed to FormatLocaleString without proper sanitization. An attacker can overwrite arbitrary memory regions, enabling a wide range of attacks from heap overflow to remote code execution. This issue has been patched in versions 6.9.13-28 and 7.1.2-2. (CVE-2025-55298)


Affected Packages:

ImageMagick


Issue Correction:
Run dnf update ImageMagick --releasever 2023.8.20250915 or dnf update --advisory ALAS2023-2025-1182 --releasever 2023.8.20250915 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    ImageMagick-6.9.12.82-1.amzn2023.0.11.aarch64
    ImageMagick-perl-debuginfo-6.9.12.82-1.amzn2023.0.11.aarch64
    ImageMagick-c++-debuginfo-6.9.12.82-1.amzn2023.0.11.aarch64
    ImageMagick-c++-devel-6.9.12.82-1.amzn2023.0.11.aarch64
    ImageMagick-perl-6.9.12.82-1.amzn2023.0.11.aarch64
    ImageMagick-devel-6.9.12.82-1.amzn2023.0.11.aarch64
    ImageMagick-debuginfo-6.9.12.82-1.amzn2023.0.11.aarch64
    ImageMagick-c++-6.9.12.82-1.amzn2023.0.11.aarch64
    ImageMagick-doc-6.9.12.82-1.amzn2023.0.11.aarch64
    ImageMagick-debugsource-6.9.12.82-1.amzn2023.0.11.aarch64
    ImageMagick-libs-debuginfo-6.9.12.82-1.amzn2023.0.11.aarch64
    ImageMagick-libs-6.9.12.82-1.amzn2023.0.11.aarch64

src:
    ImageMagick-6.9.12.82-1.amzn2023.0.11.src

x86_64:
    ImageMagick-c++-debuginfo-6.9.12.82-1.amzn2023.0.11.x86_64
    ImageMagick-c++-devel-6.9.12.82-1.amzn2023.0.11.x86_64
    ImageMagick-6.9.12.82-1.amzn2023.0.11.x86_64
    ImageMagick-perl-6.9.12.82-1.amzn2023.0.11.x86_64
    ImageMagick-perl-debuginfo-6.9.12.82-1.amzn2023.0.11.x86_64
    ImageMagick-debugsource-6.9.12.82-1.amzn2023.0.11.x86_64
    ImageMagick-debuginfo-6.9.12.82-1.amzn2023.0.11.x86_64
    ImageMagick-devel-6.9.12.82-1.amzn2023.0.11.x86_64
    ImageMagick-c++-6.9.12.82-1.amzn2023.0.11.x86_64
    ImageMagick-doc-6.9.12.82-1.amzn2023.0.11.x86_64
    ImageMagick-libs-debuginfo-6.9.12.82-1.amzn2023.0.11.x86_64
    ImageMagick-libs-6.9.12.82-1.amzn2023.0.11.x86_64