Back to Database
Status published
Low
CVE-2025-46393
In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size...
Vulnerability Description
In multispectral MIFF image processing in ImageMagick before 7.1.1-44, packet_size is mishandled (related to the rendering of all channels in an arbitrary order).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-46393
Credits & Attribution
No credits recorded in the NVD database.
References
More from ImageMagick
View All →CVE-2025-69204
ImageMagick converting a malicious MVG file to SVG caused an integer overflow.
Medium
5.3
CVE-2025-68950
Magick's failure to limit MVG mutual references forming a loop
Medium
4
CVE-2025-68618
Magick's failure to limit the depth of SVG file reads caused a DoS attack.
Medium
5.3
CVE-2025-68469
ImageMagick vulnerable to heap-buffer-overflow
Low
2
CVE-2025-66628
ImageMagick is vulnerable to an Integer Overflow in TIM decoder leading to out of bounds read (32-bit only)
High
7.5
Affected Vendor
ImageMagick
View all reports →Affected Software
ImageMagick
Vulnerable Versions:
0
Timeline
Official Publish:
April 23rd, 2025
Last Modified:
April 23rd, 2025
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.