CVE-2014-9842: High severity openSUSE openSUSE vulnerability
Fixed a memory leak in psd handling.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=f9ef11671c41da4cf973d0d880af1cdfbd127860
Other sources
Memory leak in the ReadPSDLayers function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (memory consumption) via unspecified vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What software is affected by CVE-2014-9842?
CVE-2014-9842 affects various versions of ImageMagick and several distributions such as openSUSE and Ubuntu.
What is the severity of CVE-2014-9842?
The severity of CVE-2014-9842 is considered to reflect a memory leak vulnerability in handling PSD files.
How do I fix CVE-2014-9842?
To fix CVE-2014-9842, users should update their ImageMagick installation to the latest version that includes the relevant security patch.
Is CVE-2014-9842 exploitable remotely?
CVE-2014-9842 may be exploitable remotely if the vulnerable version of ImageMagick is used in a web application processing user-uploaded PSD files.
When was CVE-2014-9842 publicly disclosed?
CVE-2014-9842 was publicly disclosed on March 12, 2016, in a security announcement on the oss-sec mailing list.