CVE-2014-9850: High severity openSUSE openSUSE vulnerability
Limit thread when thread limit is 0. It is a logic error that could lead to resource exhaustion.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=2257d1eadd02d89d225fce21013a1219d221dc7d
Other sources
Logic error in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (resource consumption).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9850?
CVE-2014-9850 has a medium severity due to its potential to cause resource exhaustion.
How do I fix CVE-2014-9850?
To fix CVE-2014-9850, upgrade to a version of ImageMagick that includes the patched code addressing the logic error.
Which software is affected by CVE-2014-9850?
CVE-2014-9850 affects various versions of ImageMagick and several distributions, including openSUSE, SUSE Linux Enterprise, and Ubuntu.
What type of vulnerability is CVE-2014-9850?
CVE-2014-9850 is a logical error that can lead to resource exhaustion if a thread limit is set to 0.
Is there a way to mitigate CVE-2014-9850 without upgrading?
Mitigation of CVE-2014-9850 without upgrading is limited, but managing thread settings may help reduce exposure.