CVE-2014-9849: High severity openSUSE openSUSE vulnerability
Avoid a crash in png coder due to uninitialized pointer.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=6330ab1048b62ab34e957447d81e35e1dde60d2e
Other sources
The png coder in ImageMagick allows remote attackers to cause a denial of service (crash).
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9849?
CVE-2014-9849 has a moderate severity rating due to the potential for application crashes caused by uninitialized pointers.
How do I fix CVE-2014-9849?
To fix CVE-2014-9849, update ImageMagick to version 6.8.9-10 or later, where the issue is addressed.
Which versions of ImageMagick are affected by CVE-2014-9849?
CVE-2014-9849 affects ImageMagick versions prior to 6.8.9-10.
Can CVE-2014-9849 lead to exploits?
CVE-2014-9849 is primarily a crash vulnerability and does not directly lead to exploitation; however, it may be used as a denial of service vector.
What platforms are affected by CVE-2014-9849?
CVE-2014-9849 affects multiple platforms including openSUSE, SUSE Linux Enterprise, and Ubuntu versions.