CVE-2014-1947
published 2020-02-17CVE-2014-1947: Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service…
PriorityP345high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EXPLOIT
EPSS
7.02%
93.5th percentile
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than CVE-2014-2030.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | graphicsmagick | < graphicsmagick 1.3.20-1 (bookworm) | graphicsmagick 1.3.20-1 (bookworm) |
| debian | imagemagick | < graphicsmagick 1.3.20-1 (bookworm) | graphicsmagick 1.3.20-1 (bookworm) |
| debian | imagemagick | < imagemagick 8:6.7.7.10+dfsg-1 (bookworm) | imagemagick 8:6.7.7.10+dfsg-1 (bookworm) |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.20-1 | 1.3.20-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.20-1 | 1.3.20-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.20-1 | 1.3.20-1 |
| graphicsmagick | graphicsmagick | >= 0 < 1.3.20-1 | 1.3.20-1 |
| imagemagick | imagemagick | <= 6.5.4 | — |
| imagemagick | imagemagick | — | — |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10+dfsg-1 | 8:6.7.7.10+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10+dfsg-1 | 8:6.7.7.10+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10+dfsg-1 | 8:6.7.7.10+dfsg-1 |
| imagemagick | imagemagick | >= 0 < 8:6.7.7.10+dfsg-1 | 8:6.7.7.10+dfsg-1 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_software_development_kit | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jfcr-jpxh-mcqv: Stack-based buffer overflow in the WritePSDImage function in coders/psd
ghsa_unreviewed·2022-05-17·CVSS 8.8
CVE-2014-1947 [HIGH] GHSA-jfcr-jpxh-mcqv: Stack-based buffer overflow in the WritePSDImage function in coders/psd
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than CVE-2014-2030.
GHSA
GHSA-8x3c-597h-8r5w: Stack-based buffer overflow in the WritePSDImage function in coders/psd
ghsa_unreviewed·2022-05-17·CVSS 7.8
CVE-2014-2030 [HIGH] GHSA-8x3c-597h-8r5w: Stack-based buffer overflow in the WritePSDImage function in coders/psd
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-1947.
OSV
CVE-2014-1947: Stack-based buffer overflow in the WritePSDImage function in coders/psd
osv·2020-02-17·CVSS 7.8
CVE-2014-1947 [HIGH] CVE-2014-1947: Stack-based buffer overflow in the WritePSDImage function in coders/psd
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than CVE-2014-2030.
OSV
CVE-2014-2030: Stack-based buffer overflow in the WritePSDImage function in coders/psd
osv·2020-02-06·CVSS 7.8
CVE-2014-2030 [HIGH] CVE-2014-2030: Stack-based buffer overflow in the WritePSDImage function in coders/psd
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-1947.
Debian
CVE-2014-1947: graphicsmagick - Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in Ima...
vendor_debian·2014·CVSS 7.8
CVE-2014-1947 [HIGH] CVE-2014-1947: graphicsmagick - Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in Ima...
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than CVE-2014-2030.
Scope: local
bookworm: resolved (fixed in 1.3.20-1)
bullseye: resolved (fixed in 1.3.20-1)
forky: resolved (fixed in 1.3.20-1)
sid: resolved (fixed in 1.3.20-1)
trixie: resolved (fixed in 1.3.20-1)
Debian
CVE-2014-2030: imagemagick - Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in Ima...
vendor_debian·2014·CVSS 7.8
CVE-2014-2030 [HIGH] CVE-2014-2030: imagemagick - Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in Ima...
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-1947.
Scope: local
bookworm: resolved (fixed in 8:6.7.7.10+dfsg-1)
bullseye: resolved (fixed in 8:6.7.7.10+dfsg-1)
forky: resolved (fixed in 8:6.7.7.10+dfsg-1)
sid: resolved (fixed in 8:6.7.7.10+dfsg-1)
trixie: resolved (fixed in 8:6.7.7.10+dfsg-1)
Red Hat
ImageMagick: PSD writing layer name buffer overflow ("L%06ld")
vendor_redhat·2013-11-14·CVSS 7.8
CVE-2014-2030 [HIGH] ImageMagick: PSD writing layer name buffer overflow ("L%06ld")
ImageMagick: PSD writing layer name buffer overflow ("L%06ld")
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick, possibly 6.8.8-5, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PSD image, involving the L%06ld string, a different vulnerability than CVE-2014-1947.
Statement: Not vulnerable. This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5 and 6.
Package: ImageMagick (OpenShift Enterprise 1) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 5) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 6) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 7) - Not affected
Package: ImageMagick (Red Hat OpenShif
Red Hat
ImageMagick: PSD writing layer name buffer overflow ("L%02ld")
vendor_redhat·2013-11-14·CVSS 7.8
CVE-2014-1947 [HIGH] ImageMagick: PSD writing layer name buffer overflow ("L%02ld")
ImageMagick: PSD writing layer name buffer overflow ("L%02ld")
Stack-based buffer overflow in the WritePSDImage function in coders/psd.c in ImageMagick 6.5.4 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number of layers in a PSD image, involving the L%02ld string, a different vulnerability than CVE-2014-2030.
Package: ImageMagick (OpenShift Enterprise 1) - Not affected
Package: ImageMagick (Red Hat Enterprise Linux 5) - Will not fix
Package: ImageMagick (Red Hat Enterprise Linux 6) - Will not fix
Package: ImageMagick (Red Hat Enterprise Linux 7) - Not affected
Package: ImageMagick (Red Hat OpenShift Enterprise 2) - Not affected
No detection rules found.
Bugzilla
CVE-2014-3561 ovirt-engine-log-collector: database password disclosed in process listing
bugzilla·2014-07-24·CVSS 2.1
CVE-2014-3561 [LOW] CVE-2014-3561 ovirt-engine-log-collector: database password disclosed in process listing
CVE-2014-3561 ovirt-engine-log-collector: database password disclosed in process listing
IssueDescription:
It was found that rhevm-log-collector called sosreport with the PostgreSQL database password passed as a command line parameter. A local attacker could read this password by monitoring a process listing. The password would also be written to a log file, which could potentially be read by a local attacker.
Discussion:
Acknowledgements:
This issue was discovered by David Jorm of Red Hat Product Security.
---
Both dependencies verified, setting verified.
---
This issue has been addressed in the following products:
RHEV Manager version 3.4
Via RHSA-2014:1947 https://rhn.redhat.com/errata/RHSA-2014-1947.html
Bugzilla
CVE-2014-2030 ImageMagick: PSD writing layer name buffer overflow ("L%06ld")
bugzilla·2014-04-02·CVSS 7.8
CVE-2014-2030 [HIGH] CVE-2014-2030 ImageMagick: PSD writing layer name buffer overflow ("L%06ld")
CVE-2014-2030 ImageMagick: PSD writing layer name buffer overflow ("L%06ld")
A buffer overflow flaw affecting ImageMagick when creating PSD images was reported. The vulnerability is similar to CVE-2014-1947, except that CVE-2014-2030's format string is "L%06ld" instead of CVE-2014-1947's "L%02ld" due to commit r1448: http://trac.imagemagick.org/changeset/1448
Fixed by commit r13736: http://trac.imagemagick.org/changeset/13736
Discussion:
The related CVE-2014-1947 issue is tracked via bug 1064098.
---
Statement:
Not vulnerable. This issue did not affect the versions of ImageMagick as shipped with Red Hat Enterprise Linux 5 and 6.
---
PSD writing layer name buffer overflow vulnerability poses a significant risk to digital design projects. It can lead to data corruption or even syste
Bugzilla
CVE-2014-1947 CVE-2014-2030 ImageMagick, GraphicsMagick: buffer overflow when handling PSD images [fedora-all]
bugzilla·2014-04-01·CVSS 7.8
CVE-2014-1947 [HIGH] CVE-2014-1947 CVE-2014-2030 ImageMagick, GraphicsMagick: buffer overflow when handling PSD images [fedora-all]
CVE-2014-1947 CVE-2014-2030 ImageMagick, GraphicsMagick: buffer overflow when handling PSD images [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availa
Bugzilla
CVE-2014-1947 CVE-2014-2030 ImageMagick, GraphicsMagick: buffer overflow when handling PSD images [epel-5]
bugzilla·2014-04-01·CVSS 7.8
CVE-2014-1947 [HIGH] CVE-2014-1947 CVE-2014-2030 ImageMagick, GraphicsMagick: buffer overflow when handling PSD images [epel-5]
CVE-2014-1947 CVE-2014-2030 ImageMagick, GraphicsMagick: buffer overflow when handling PSD images [epel-5]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avail
Bugzilla
CVE-2014-1947 CVE-2014-2030 ImageMagick, GraphicsMagick: buffer overflow when handling PSD images [epel-6]
bugzilla·2014-04-01·CVSS 7.8
CVE-2014-1947 [HIGH] CVE-2014-1947 CVE-2014-2030 ImageMagick, GraphicsMagick: buffer overflow when handling PSD images [epel-6]
CVE-2014-1947 CVE-2014-2030 ImageMagick, GraphicsMagick: buffer overflow when handling PSD images [epel-6]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when avail
Bugzilla
CVE-2014-1947 CVE-2014-2030 ImageMagick: buffer overflow when handling PSD images [fedora-all]
bugzilla·2014-02-20·CVSS 7.8
CVE-2014-1947 [HIGH] CVE-2014-1947 CVE-2014-2030 ImageMagick: buffer overflow when handling PSD images [fedora-all]
CVE-2014-1947 CVE-2014-2030 ImageMagick: buffer overflow when handling PSD images [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please not
Bugzilla
CVE-2014-1947 ImageMagick: PSD writing layer name buffer overflow ("L%02ld")
bugzilla·2014-02-12·CVSS 7.8
CVE-2014-1947 [HIGH] CVE-2014-1947 ImageMagick: PSD writing layer name buffer overflow ("L%02ld")
CVE-2014-1947 ImageMagick: PSD writing layer name buffer overflow ("L%02ld")
A buffer overflow flaw affecting ImageMagick versions prior to 6.8.8-5 when handling PSD images was reported:
http://secunia.com/advisories/56844/
Diffing ImageMagick-6.8.7/coders/psd.c and ImageMagick-6.8.8/coders/psd.c, it looks like the flaw may be FormatLocaleString() writing the amount of 6 long integers (approximately 48 bytes) into a buffer (layer_name) that is only 4 bytes:
""
@@ -1224,7 +1224,7 @@
Allocate layered image.
*/
layer_info[i].image=CloneImage(image,layer_info[i].page.width,
- layer_info[i].page.height == ~0U ? 1 : layer_info[i].page.height,
+ layer_info[i].page.height == ~0UL ? 1 : layer_info[i].page.height,
MagickFalse,&image->exception);
if (layer_info[i].image == (Image *) NULL)
{
@@ -2
http://www.openwall.com/lists/oss-security/2014/02/12/13http://www.openwall.com/lists/oss-security/2014/02/12/2http://www.openwall.com/lists/oss-security/2014/02/13/2http://www.openwall.com/lists/oss-security/2014/02/13/5http://www.openwall.com/lists/oss-security/2014/02/19/13https://bugzilla.redhat.com/show_bug.cgi?id=1064098https://www.suse.com/support/update/announcement/2014/suse-su-20140359-1.htmlhttp://www.openwall.com/lists/oss-security/2014/02/12/13http://www.openwall.com/lists/oss-security/2014/02/12/2http://www.openwall.com/lists/oss-security/2014/02/13/2http://www.openwall.com/lists/oss-security/2014/02/13/5http://www.openwall.com/lists/oss-security/2014/02/19/13https://bugzilla.redhat.com/show_bug.cgi?id=1064098https://www.suse.com/support/update/announcement/2014/suse-su-20140359-1.html
2020-02-17
Published