CVE Vulnerabilities

CVE-2025-55212

Divide By Zero

Published: Aug 26, 2025 | Modified: Sep 02, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
3.7 LOW
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Ubuntu
MEDIUM

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-28 and 7.1.2-2, passing a geometry string containing only a colon (:) to montage -geometry leads GetGeometry() to set width/height to 0. Later, ThumbnailImage() divides by these zero dimensions, triggering a crash (SIGFPE/abort), resulting in a denial of service. This issue has been patched in versions 6.9.13-28 and 7.1.2-2.

Weakness

The product divides a value by zero.

Affected Software

Name Vendor Start Version End Version
Imagemagick Imagemagick * 6.9.13-28 (excluding)
Imagemagick Imagemagick 7.0.0-0 (including) 7.1.2-2 (excluding)
Imagemagick Ubuntu esm-apps/noble *
Imagemagick Ubuntu noble *
Imagemagick Ubuntu plucky *

References