Listen to this Post
The vulnerability CVE-2025-57803 is an integer overflow in the BMP image coder of ImageMagick. It occurs on 32-bit systems where the `size_t` type is 4 bytes. The flaw exists in the `coders/bmp.c` file. When processing a malicious BMP file with specific large dimensions, the calculation `extent = image->columns bmp_info.bits_per_pixel` at line 1120 overflows. This integer overflow truncates the `extent` variable to a small value, such as zero. The subsequent calculation for `bytes_per_line` then also results in a zero. A patched function, BMPOverflowCheck(), was added but is placed after the overflow has already occurred. It checks the already-truncated value and fails to detect the overflow. This allows the code to proceed with corrupted data, leading to an AddressSanitizer crash and a Denial-of-Service condition when the application attempts to allocate or process memory based on these invalid calculations.
Platform: ImageMagick
Version: 7.1.2-2 to 7.1.2-5
Vulnerability : Integer Overflow
Severity: Critical
date: 2025
Prediction: 2025-03-15
What Undercode Say:
./configure --host=i686-pc-linux-gnu CFLAGS="-fsanitize=address,undefined" export MAGICK_WIDTH_LIMIT=2000000000 ./utilities/magick identify overflow.bmp
// Vulnerable code (coders/bmp.c:1120-1122) extent = image->columns bmp_info.bits_per_pixel; // OVERFLOW! bytes_per_line = 4((extent+31)/32); if (BMPOverflowCheck(bytes_per_line, image->rows) != MagickFalse) // Check too late
PoC BMP Generator
width = 0x20000000
dib_header = struct.pack('<i', width)
How Exploit:
Craft malicious BMP.
Upload to server.
Trigger integer overflow.
Cause application crash.
Protection from this CVE
Apply complete patch.
Use 64-bit systems.
Enforce default resource limits.
Impact:
Denial of Service.
Application crash.
Service unavailability.
🎯Let’s Practice Exploiting & Learn Patching For Free:
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

