CVE-2014-9853: Medium severity ImageMagick ImageMagick vulnerability
Avoid a memory leak in rle file handling.
CVE assignment:
http://seclists.org/oss-sec/2016/q2/459
Upstream patches related to rle file handling:
https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=74b6cb6000b678e3e7bac553177052cb15b02cb6 https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=36ed9419a68cb1356b1843b48cc12788179cdaee https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=2d90693af41a363a988a9db3a91a15f9ca7c7370 https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=90a405ba3e329e7e080addadac377dd4235671d3
Other sources
Memory leak in coders/rle.c in ImageMagick allows remote attackers to cause a denial of service (memory consumption) via a crafted rle file.
— NVD
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9853?
CVE-2014-9853 is classified with moderate severity due to its potential to cause a memory leak.
How do I fix CVE-2014-9853?
To fix CVE-2014-9853, you should update ImageMagick to a version that includes the relevant patches for rle file handling.
Which software is affected by CVE-2014-9853?
CVE-2014-9853 affects multiple versions of ImageMagick prior to 6.9.4 and various SUSE and Ubuntu distributions.
What type of vulnerability is CVE-2014-9853?
CVE-2014-9853 is a memory leak vulnerability occurring in the rle file handling of ImageMagick.
Is CVE-2014-9853 a local or remote vulnerability?
CVE-2014-9853 is typically exploited locally, as it requires manipulation of specific file types.