USN-7433-1: GraphicsMagick vulnerabilities
14 April 2025
Several security issues were fixed in GraphicsMagick.
Releases
Packages
- graphicsmagick - collection of image processing tools
Details
It was discovered that GraphicsMagick did not properly limit image
dimensions, which could lead to excessive memory consumption. An attacker
could possibly use this issue to cause a denial of service.
(CVE-2025-27795)
It was discovered that GraphicsMagick did not properly handle certain
memory operations, which could lead to a out-of-bounds memory access. An
attacker could possibly use this issue to leak sensitive information.
This issue only affected Ubuntu 24.10. (CVE-2025-27796)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 24.10
Ubuntu 24.04
-
graphicsmagick
-
1.4+really1.3.42-1.1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 22.04
-
graphicsmagick
-
1.4+really1.3.38-1ubuntu0.1+esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.