First published: Tue Jun 07 2016(Updated: )
Fix another out of bound problem in rle file. CVE assignment: <a href="http://seclists.org/oss-sec/2016/q2/459">http://seclists.org/oss-sec/2016/q2/459</a> Upstream patch: <a href="https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=36ed9419a68cb1356b1843b48cc12788179cdaee">https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=36ed9419a68cb1356b1843b48cc12788179cdaee</a>
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Studio Onsite | =1.3 | |
openSUSE | =13.2 | |
openSUSE Leap | =42.1 | |
SUSE Linux Enterprise Debuginfo | =11.0-sp4 | |
SUSE Linux Enterprise Desktop | =12.0-sp1 | |
SUSE Linux Enterprise Server | =11.0-sp4 | |
SUSE Linux Enterprise Server | =12.0-sp1 | |
SUSE Linux Enterprise Software Development Kit | =11.0-sp4 | |
SUSE Linux Enterprise Software Development Kit | =12.0-sp1 | |
SUSE Linux Enterprise Workstation Extension | =12.0-sp1 | |
Ubuntu Linux | =12.04 | |
Ubuntu Linux | =14.04 | |
Ubuntu Linux | =16.04 | |
Ubuntu Linux | =16.10 | |
ImageMagick ImageMagick | =6.8.8-9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9844 is classified as a medium severity vulnerability due to the possibility of causing denial of service through an out-of-bounds read.
To mitigate CVE-2014-9844, update to the latest version of ImageMagick or apply the relevant patch from the project's repository.
CVE-2014-9844 affects several software versions including ImageMagick versions before 6.8.9-9 and various distributions like SUSE Studio and Ubuntu.
CVE-2014-9844 is an out-of-bounds read vulnerability found in the processing of RLE files in ImageMagick.
No, CVE-2014-9844 does not lead to remote code execution but can lead to denial of service through crashes.