CVE-2014-9844

MEDIUM

ImageMagick 6.8.9.9 - DoS

Title source: llm

Description

The ReadRLEImage function in coders/rle.c in ImageMagick 6.8.9.9 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted image file.

Scores

CVSS v3 5.5
EPSS 0.0029
EPSS Percentile 52.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Classification

CWE
CWE-125
Status published

Affected Products (16)

suse/studio_onsite
opensuse/opensuse
opensuse_project/leap
opensuse_project/suse_linux_enterprise_debuginfo
opensuse_project/suse_linux_enterprise_desktop
opensuse_project/suse_linux_enterprise_server
opensuse_project/suse_linux_enterprise_server
opensuse_project/suse_linux_enterprise_software_development_kit
opensuse_project/suse_linux_enterprise_software_development_kit
opensuse_project/suse_linux_enterprise_workstation_extension
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
canonical/ubuntu_linux
imagemagick/imagemagick
... and 1 more

Timeline

Published Mar 20, 2017
Tracked Since Feb 18, 2026