{"id":"ECHO-8c44-9b92-aae4","summary":"Possible integer overflow issue in the BMP decoder. Will only affect 32-bit builds so not applicable. There is a\nfix that doesn't apply cleanly to our build because there is another patch to apply before it. Again it's irrelevant because\nthe issue will only affect 32-bit builds.\nhttps://security-tracker.debian.org/tracker/CVE-2025-62171\nhttps://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9pp9-cfwx-54rm\nhttps://github.com/ImageMagick/ImageMagick/commit/cea1693e2ded51b4cc91c70c54096cbed1691c00\n","modified":"2026-09-15T03:33:42.736941426Z","published":"2026-01-29T00:52:40.257925Z","withdrawn":"2025-10-28T08:30:08.760Z","upstream":["CVE-2025-62171"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2025-62171"}],"affected":[{"package":{"name":"imagemagick","ecosystem":"Echo","purl":"pkg:deb/echo/imagemagick"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8:7.1.1.43+dfsg1-1+deb13u2"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-8c44-9b92-aae4.json"}}],"schema_version":"1.9.0"}