CVE-2014-9847: Buffer Overflow
Don't try to handle a "previous" image in the JNG decoder.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=f4ece8c7c462c5449138f39401f66318b9ab0430
Other sources
The jng decoder in ImageMagick 6.8.9.9 allows remote attackers to have an unspecified impact.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9847?
CVE-2014-9847 is classified as a moderate severity vulnerability.
How do I fix CVE-2014-9847?
To fix CVE-2014-9847, you should update ImageMagick to the latest patched version.
Which versions of ImageMagick are affected by CVE-2014-9847?
CVE-2014-9847 affects ImageMagick versions prior to 6.8.9-9.
What platform vulnerabilities are associated with CVE-2014-9847?
CVE-2014-9847 impacts various platforms including openSUSE, Ubuntu, and SUSE Linux Enterprise products.
What type of vulnerability is CVE-2014-9847?
CVE-2014-9847 is a decoding vulnerability in the JNG decoder component of ImageMagick.