CVE-2014-9851: Input Validation
ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (application crash).
Other sources
In psd file handling fixed parsing resource block and avoid a crash.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patch:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=33b2d377b94eb738011bc7d5e90ca0a16ce4d471
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9851?
CVE-2014-9851 has a severity rating that reflects a denial of service vulnerability allowing attackers to crash applications.
How do I fix CVE-2014-9851?
To fix CVE-2014-9851, update ImageMagick to a version that includes the patch addressing the vulnerability.
Which systems are affected by CVE-2014-9851?
CVE-2014-9851 affects various versions of ImageMagick on platforms such as openSUSE and Ubuntu.
Can CVE-2014-9851 be exploited remotely?
Yes, CVE-2014-9851 can be exploited remotely through specially crafted PSD files.
What are the consequences of CVE-2014-9851?
The consequence of CVE-2014-9851 is an application crash resulting in potential denial of service.