[CVE-2025-65955]Use-after-free/double-free risk in Options::fontFamily when clearing family

January 13, 2026 00:01:22
[CVE-2025-65955]Use-after-free/double-free risk in Options::fontFamily when clearing family
The Daily Cyberspace Information
[CVE-2025-65955]Use-after-free/double-free risk in Options::fontFamily when clearing family

Jan 13 2026 | 00:01:22

/

Show Notes

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string.

View Full Transcript

Episode Transcript

[CVE-2025-65955]Use-after-free/double-free risk in Options::fontFamily when clearing family Description ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-9 and 6.9.13-34, there is a vulnerability in ImageMagick’s Magick++ layer that manifests when Options::fontFamily is invoked with an empty string. Vulnerability Details Clearing a font family calls RelinquishMagickMemory on _drawInfo->font, freeing the font string but leaving _drawInfo->font pointing to freed memory while _drawInfo->family is set to that (now-invalid) pointer. Any later cleanup or reuse of _drawInfo->font re-frees or dereferences dangling memory. DestroyDrawInfo and other setters (Options::font, Image::font) assume _drawInfo->font remains valid, so destruction or subsequent updates trigger crashes or heap corruption. update to 7.1.2-9 or 6.9.13-34.

Other Episodes

Episode

January 12, 2026 00:03:44
Episode Cover

Information Disclosure Vulnerability in MongoDB (CVE-2025-14847)

On December 19, 2025, MongoDB disclosed information regarding a vulnerability (CVE-2025-14847) in MongoDB involving information disclosure from uninitialized heap memory. If exploited, an unauthenticated...

Listen

Episode

January 11, 2026 00:00:49
Episode Cover

【Python】Default mimetype known files writeable on Windows

There is a defect in the CPython standard library module “mimetypes” where on Windows the default list of known file locations are writable meaning...

Listen

Episode

January 12, 2026 00:04:19
Episode Cover

The Apache Software Foundation has released Apache HTTP Server 2.4.66.

The Apache Software Foundation has released Apache HTTP Server 2.4.66 to address multiple vulnerabilities in the Apache HTTP Server 2.4 series.

Listen