CVE-2014-9846: Buffer Overflow
Added checks to prevent overflow in rle file.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=2d90693af41a363a988a9db3a91a15f9ca7c7370
Other sources
Buffer overflow in the ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to have unspecified impact.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9846?
The severity of CVE-2014-9846 is considered to be medium due to potential risk of overflow in rle file processing.
How do I fix CVE-2014-9846?
To fix CVE-2014-9846, you should update ImageMagick to the latest version or apply the relevant patches provided by your distribution.
Which software is affected by CVE-2014-9846?
CVE-2014-9846 affects various versions of ImageMagick and distributions such as openSUSE and Ubuntu.
What vulnerabilities does CVE-2014-9846 address?
CVE-2014-9846 addresses vulnerabilities related to buffer overflow issues in the processing of rle image files.
Is CVE-2014-9846 being actively exploited in the wild?
As of the latest information, there are no confirmed reports of CVE-2014-9846 being actively exploited in the wild.