CVE-2014-9845: Buffer Overflow
Fix crash due to corrupted dib file.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=a7a7fd3ce95b7b8efb0ce1ce40f43dbbd20d8e03
Other sources
The ReadDIBImage function in coders/dib.c in ImageMagick allows remote attackers to cause a denial of service (crash) via a corrupted dib file.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9845?
CVE-2014-9845 has a moderate severity level due to the potential for application crashes when handling corrupted DIB files.
How do I fix CVE-2014-9845?
To fix CVE-2014-9845, update to the patched version of ImageMagick that addresses this vulnerability.
What platforms are affected by CVE-2014-9845?
CVE-2014-9845 affects various platforms including certain versions of SUSE Linux, openSUSE, and Ubuntu.
What type of vulnerability is CVE-2014-9845?
CVE-2014-9845 is categorized as a software crash vulnerability caused by improper handling of corrupted files.
When was CVE-2014-9845 reported?
CVE-2014-9845 was reported publicly in 2016, highlighting issues with ImageMagick's file processing.