CVE-2014-9844: Medium severity SUSE Studio onsite vulnerability
Fix another out of bound problem in rle file.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=36ed9419a68cb1356b1843b48cc12788179cdaee
Other sources
The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9844?
CVE-2014-9844 is classified as a medium severity vulnerability due to the possibility of causing denial of service through an out-of-bounds read.
How do I fix CVE-2014-9844?
To mitigate CVE-2014-9844, update to the latest version of ImageMagick or apply the relevant patch from the project's repository.
What software is affected by CVE-2014-9844?
CVE-2014-9844 affects several software versions including ImageMagick versions before 6.8.9-9 and various distributions like SUSE Studio and Ubuntu.
What type of vulnerability is CVE-2014-9844?
CVE-2014-9844 is an out-of-bounds read vulnerability found in the processing of RLE files in ImageMagick.
Can CVE-2014-9844 lead to code execution?
No, CVE-2014-9844 does not lead to remote code execution but can lead to denial of service through crashes.