{"id":"UBUNTU-CVE-2025-55212","details":"ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (\":\") to montage -geometry leads GetGeometry() to set width/height to 0. Later, ThumbnailImage() divides by these zero dimensions, triggering a crash (SIGFPE/abort), resulting in a denial of service. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.","modified":"2026-04-22T19:57:21.838595Z","published":"2025-08-26T17:15:00Z","related":["USN-7756-1"],"upstream":["CVE-2025-55212"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-55212"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-55212"},{"type":"REPORT","url":"https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-fh55-q5pj-pxgw"},{"type":"REPORT","url":"https://github.com/ImageMagick/ImageMagick/commit/5f0bcf986b8b5e90567750d31a37af502b73f2af"},{"type":"REPORT","url":"https://github.com/ImageMagick/ImageMagick/commit/43d92bf855155e8e716ecbb50ed94c2ed41ff9f6"},{"type":"REPORT","url":"https://github.com/ImageMagick/ImageMagick6/commit/3482953ef0af1e538cb776162a8d278141e0b9a0"},{"type":"REPORT","url":"https://github.com/ImageMagick/ImageMagick6/commit/5fddcf974342d8e5e02f604bc2297c038e3d4196"},{"type":"REPORT","url":"https://github.com/ImageMagick/ImageMagick/blob/0ba1b587be17543b664f7ad538e9e51e0da59d17/MagickCore/geometry.c#L355"},{"type":"REPORT","url":"https://github.com/ImageMagick/ImageMagick/blob/0ba1b587be17543b664f7ad538e9e51e0da59d17/MagickCore/resize.c#L4625-L4629"},{"type":"REPORT","url":"https://github.com/dlemstra/Magick.NET/releases/tag/14.8.1"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7756-1"}],"affected":[{"package":{"name":"imagemagick","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/imagemagick@8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2?arch=source&distro=esm-apps/noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"}]}],"versions":["8:6.9.11.60+dfsg-1.6ubuntu1","8:6.9.12.98+dfsg1-5","8:6.9.12.98+dfsg1-5.2build1","8:6.9.12.98+dfsg1-5.2build2","8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm1"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro: https://ubuntu.com/pro","binaries":[{"binary_name":"imagemagick","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"imagemagick-6-common","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"imagemagick-6.q16","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"imagemagick-6.q16hdri","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"libimage-magick-perl","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"libimage-magick-q16-perl","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"libimage-magick-q16hdri-perl","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"libmagick++-6-headers","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"libmagick++-6.q16-9t64","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"libmagick++-6.q16hdri-9t64","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2","binary_name":"libmagickcore-6-arch-config"},{"binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2","binary_name":"libmagickcore-6-headers"},{"binary_name":"libmagickcore-6.q16-7-extra","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"libmagickcore-6.q16-7t64","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"libmagickcore-6.q16hdri-7-extra","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"libmagickcore-6.q16hdri-7t64","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"libmagickwand-6-headers","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"libmagickwand-6.q16-7t64","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"libmagickwand-6.q16hdri-7t64","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"},{"binary_name":"perlmagick","binary_version":"8:6.9.12.98+dfsg1-5.2ubuntu0.1~esm2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-55212.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}