{"id":"ECHO-eab7-3e17-b4f3","summary":"The cve is that when modifying a jpeg image with imagemagic, the original image thumbnail might not modify the EXIF thumbnail.\nBut there are ways to remove the EXIF profile with like with a convert --strip command. It's just something an application needs\nto handle. The debian bug was closed and the upstream said it won't fix it.\n","modified":"2026-09-15T03:33:35.537336322Z","published":"2025-09-15T01:08:34.924912Z","withdrawn":"2025-10-28T08:30:08.760Z","upstream":["CVE-2005-0406"],"references":[{"type":"WEB","url":"https://advisory.echohq.com/cve/CVE-2005-0406"}],"affected":[{"package":{"name":"imagemagick","ecosystem":"Echo","purl":"pkg:deb/echo/imagemagick"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"8:7.1.1.43+dfsg1-1+deb13u2"}]}],"database_specific":{"source":"https://advisory.echohq.com/osv/ECHO-eab7-3e17-b4f3.json"}}],"schema_version":"1.9.0"}