CVE-2025-32460: Critical severity GraphicsMagick Graphicsmagick vulnerability
Published Apr 9, 2025
·Updated
GraphicsMagick before 8e56520 has a heap-based buffer over-read in ReadJXLImage in coders/jxl.c, related to an ImportViewPixelArea call.
Affected Software
2 affected components
GraphicsMagick Graphicsmagick<8e56520
GraphicsMagick Graphicsmagick<1.3.46
Remediation
Patch Available
Event History
Apr 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-32460?
CVE-2025-32460 is classified as a moderate severity vulnerability due to its potential for causing a heap-based buffer over-read.
2
How do I fix CVE-2025-32460?
To fix CVE-2025-32460, update GraphicsMagick to version 8e56520 or later.
3
What type of vulnerability is CVE-2025-32460?
CVE-2025-32460 is a heap-based buffer over-read vulnerability that affects the ReadJXLImage function in GraphicsMagick.
4
Which versions of GraphicsMagick are affected by CVE-2025-32460?
GraphicsMagick versions prior to 8e56520 are affected by CVE-2025-32460.
5
What impact can CVE-2025-32460 have on systems using GraphicsMagick?
CVE-2025-32460 can lead to potential information disclosure or application instability, impacting the reliability of systems using affected versions.