Vulnerability Description
ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Graphicsmagick | Graphicsmagick | < 1.3.46 |
Related Weaknesses (CWE)
References
- http://www.graphicsmagick.org/NEWS.htmlRelease Notes
- https://foss.heptapod.net/graphicsmagick/graphicsmagick/-/commit/883ebf8cae6dfa5Patch
- https://sourceforge.net/p/graphicsmagick/bugs/750/Permissions Required
FAQ
What is CVE-2025-27796?
CVE-2025-27796 is a vulnerability with a CVSS score of 4.5 (MEDIUM). ReadWPGImage in WPG in GraphicsMagick before 1.3.46 mishandles palette buffer allocation, resulting in out-of-bounds access to heap memory in ReadBlob.
How severe is CVE-2025-27796?
CVE-2025-27796 has been rated MEDIUM with a CVSS base score of 4.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-27796?
Check the references section above for vendor advisories and patch information. Affected products include: Graphicsmagick Graphicsmagick.