CVE-2014-9843: Buffer Overflow
Fixed boundary checks in DecodePSDPixels.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=b8df15144d91a19ed545893ea492363635a1cb29
Other sources
The DecodePSDPixels function in coders/psd.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact via unknown vectors.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability CVE-2014-9843 about?
CVE-2014-9843 involves a fixed boundary check issue in the DecodePSDPixels function of ImageMagick.
What are the affected versions for CVE-2014-9843?
Affected versions of ImageMagick include 6.8.8-9 and various versions of openSUSE and Ubuntu distributions.
What is the severity of CVE-2014-9843?
CVE-2014-9843 is classified as a potential vulnerability that could lead to inadequate validation of input.
How do I fix the vulnerability CVE-2014-9843?
To fix CVE-2014-9843, update ImageMagick to version 6.8.9-9 or later where the boundary checks have been fixed.
What platforms are impacted by CVE-2014-9843?
Platforms impacted by CVE-2014-9843 include openSUSE, Ubuntu, and other environments running the vulnerable versions of ImageMagick.