First published: Mon Apr 14 2025(Updated: )
It was discovered that GraphicsMagick did not properly limit image dimensions, which could lead to excessive memory consumption. An attacker could possibly use this issue to cause a denial of service. (CVE-2025-27795) It was discovered that GraphicsMagick did not properly handle certain memory operations, which could lead to a out-of-bounds memory access. An attacker could possibly use this issue to leak sensitive information. This issue only affected Ubuntu 24.10. (CVE-2025-27796)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/graphicsmagick | <1.4+really1.3.45-1ubuntu0.1 | 1.4+really1.3.45-1ubuntu0.1 |
Ubuntu | =24.10 | |
All of | ||
ubuntu/graphicsmagick | <1.4+really1.3.42-1.1ubuntu0.1~esm1 | 1.4+really1.3.42-1.1ubuntu0.1~esm1 |
Ubuntu | =24.04 | |
All of | ||
ubuntu/graphicsmagick | <1.4+really1.3.38-1ubuntu0.1+esm1 | 1.4+really1.3.38-1ubuntu0.1+esm1 |
Ubuntu | =22.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
USN-7433-1 is classified as a denial of service vulnerability due to improper image dimension limitations in GraphicsMagick.
To fix USN-7433-1, upgrade GraphicsMagick to version 1.4+really1.3.45-1ubuntu0.1 or newer.
USN-7433-1 affects the GraphicsMagick package in specific versions of Ubuntu, including 24.10, 24.04, and 22.04.
GraphicsMagick is an image processing software, and USN-7433-1 is important because it addresses a security flaw that can lead to excessive memory consumption.
If USN-7433-1 is not addressed, it could lead to a denial of service, causing systems using GraphicsMagick to become unresponsive.