CVE-2014-9848: High severity openSUSE Leap vulnerability
Avoid a memory leak in quantum management.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=44675e8e48977bbeb1cafade861db2d777a5c7ae
Other sources
Memory leak in ImageMagick allows remote attackers to cause a denial of service (memory consumption).
— NVD
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9848?
CVE-2014-9848 has been classified with moderate severity due to the memory leak in quantum management.
How do I fix CVE-2014-9848?
To fix CVE-2014-9848, apply the relevant patches provided by the respective vendor for the affected software.
What software is affected by CVE-2014-9848?
CVE-2014-9848 affects various versions of ImageMagick and multiple distributions of openSUSE and Ubuntu.
Can CVE-2014-9848 lead to a denial of service?
Yes, CVE-2014-9848 can potentially lead to denial of service due to memory exhaustion.
Is there a workaround for CVE-2014-9848?
Currently, there is no officially recommended workaround for CVE-2014-9848 other than applying the patch.