CVE-2014-2030

Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-1947.
Configurations

Configuration 1 (hide)

cpe:2.3:a:imagemagick:imagemagick:6.8.8-5:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*

Configuration 3 (hide)

OR cpe:2.3:o:opensuse:opensuse:11.4:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*
cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*

History

21 Nov 2024, 02:05

Type Values Removed Values Added
References () http://lists.opensuse.org/opensuse-updates/2014-03/msg00032.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-updates/2014-03/msg00032.html - Mailing List, Third Party Advisory
References () http://lists.opensuse.org/opensuse-updates/2014-03/msg00039.html - Mailing List, Third Party Advisory () http://lists.opensuse.org/opensuse-updates/2014-03/msg00039.html - Mailing List, Third Party Advisory
References () http://ubuntu.com/usn/usn-2132-1 - Third Party Advisory () http://ubuntu.com/usn/usn-2132-1 - Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2014/02/12/2 - Mailing List, Patch, Third Party Advisory () http://www.openwall.com/lists/oss-security/2014/02/12/2 - Mailing List, Patch, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2014/02/13/5 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2014/02/13/5 - Mailing List, Third Party Advisory
References () http://www.openwall.com/lists/oss-security/2014/02/19/13 - Mailing List, Third Party Advisory () http://www.openwall.com/lists/oss-security/2014/02/19/13 - Mailing List, Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=1064098 - Issue Tracking, Patch, Third Party Advisory () https://bugzilla.redhat.com/show_bug.cgi?id=1064098 - Issue Tracking, Patch, Third Party Advisory
References () https://web.archive.org/web/20090120112751/http://trac.imagemagick.org/changeset/13736 - Patch, Third Party Advisory () https://web.archive.org/web/20090120112751/http://trac.imagemagick.org/changeset/13736 - Patch, Third Party Advisory

Information

Published : 2020-02-06 15:15

Updated : 2024-11-21 02:05


NVD link : CVE-2014-2030

Mitre link : CVE-2014-2030

CVE.ORG link : CVE-2014-2030


JSON object : View

Products Affected

canonical

  • ubuntu_linux

opensuse

  • opensuse

imagemagick

  • imagemagick
CWE
CWE-787

Out-of-bounds Write