First published: Tue Jun 07 2016(Updated: )
Avoid a memory leak in rle file handling. CVE assignment: <a href="http://seclists.org/oss-sec/2016/q2/459">http://seclists.org/oss-sec/2016/q2/459</a> Upstream patches related to rle file handling: <a href="https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=74b6cb6000b678e3e7bac553177052cb15b02cb6">https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=74b6cb6000b678e3e7bac553177052cb15b02cb6</a> <a href="https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=36ed9419a68cb1356b1843b48cc12788179cdaee">https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=36ed9419a68cb1356b1843b48cc12788179cdaee</a> <a href="https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=2d90693af41a363a988a9db3a91a15f9ca7c7370">https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=2d90693af41a363a988a9db3a91a15f9ca7c7370</a> <a href="https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=90a405ba3e329e7e080addadac377dd4235671d3">https://anonscm.debian.org/cgit/collab-maint/imagemagick.git/commit/?h=debian-patches/6.8.9.9-4-for-upstream&id=90a405ba3e329e7e080addadac377dd4235671d3</a>
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
ImageMagick | <6.9.4-0 | |
SUSE Linux Enterprise Debuginfo | =11-sp4 | |
openSUSE | =42.2 | |
SUSE Linux | =42.1 | |
SUSE Linux | =13.2 | |
SUSE Linux Enterprise Software Development Kit | =11.0-sp4 | |
SUSE Linux Enterprise Desktop | =12-sp1 | |
SUSE Linux Enterprise Server | =11-sp4 | |
SUSE Linux Enterprise Server | =12-sp1 | |
SUSE Linux Enterprise Software Development Kit | =12-sp1 | |
SUSE Linux Workstation Extension | =12-sp1 | |
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =16.10 | |
ImageMagick |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9853 is classified with moderate severity due to its potential to cause a memory leak.
To fix CVE-2014-9853, you should update ImageMagick to a version that includes the relevant patches for rle file handling.
CVE-2014-9853 affects multiple versions of ImageMagick prior to 6.9.4 and various SUSE and Ubuntu distributions.
CVE-2014-9853 is a memory leak vulnerability occurring in the rle file handling of ImageMagick.
CVE-2014-9853 is typically exploited locally, as it requires manipulation of specific file types.